Claude-Skills quality-manager-qms-iso13485

install
source · Clone the upstream repo
git clone https://github.com/borghei/Claude-Skills
Claude Code · Install into ~/.claude/skills/
T=$(mktemp -d) && git clone --depth=1 https://github.com/borghei/Claude-Skills "$T" && mkdir -p ~/.claude/skills && cp -r "$T/ra-qm-team/quality-manager-qms-iso13485" ~/.claude/skills/borghei-claude-skills-quality-manager-qms-iso13485 && rm -rf "$T"
manifest: ra-qm-team/quality-manager-qms-iso13485/SKILL.md
source content

Quality Manager - QMS ISO 13485 Specialist

ISO 13485:2016 Quality Management System implementation, maintenance, and certification support for medical device organizations.


Table of Contents


QMS Implementation Workflow

Implement ISO 13485:2016 compliant quality management system from gap analysis through certification.

Workflow: Initial QMS Implementation

  1. Conduct gap analysis against ISO 13485:2016 requirements
  2. Document current state vs. required state for each clause
  3. Prioritize gaps by:
    • Regulatory criticality
    • Risk to product safety
    • Resource requirements
  4. Develop implementation roadmap with milestones
  5. Establish Quality Manual per Clause 4.2.2:
    • QMS scope with justified exclusions
    • Process interactions
    • Procedure references
  6. Create required documented procedures:
    • Document control (4.2.3)
    • Record control (4.2.4)
    • Internal audit (8.2.4)
    • Nonconforming product (8.3)
    • Corrective action (8.5.2)
    • Preventive action (8.5.3)
  7. Deploy processes with training
  8. Validation: Gap analysis complete; Quality Manual approved; all required procedures documented and trained

Gap Analysis Matrix

ClauseRequirementCurrent StateGapPriorityAction
4.2.2Quality ManualNot documentedMajorHighCreate QM
4.2.3Document controlInformalModerateHighFormalize SOP
5.6Management reviewAd hocMajorHighEstablish schedule
7.3Design controlPartialModerateMediumComplete procedures
8.2.4Internal auditNoneMajorHighCreate program

QMS Structure

LevelDocument TypePurposeExample
1Quality ManualQMS overview, policyQM-001
2ProceduresHow processes workSOP-02-001
3Work InstructionsTask-level detailWI-06-012
4RecordsEvidence of conformityTraining records

Required Procedure List

ClauseProcedureMinimum Content
4.2.3Document ControlApproval, review, distribution, obsolete control
4.2.4Record ControlIdentification, storage, retention, disposal
8.2.4Internal AuditProgram, auditor qualification, reporting
8.3Nonconforming ProductIdentification, segregation, disposition
8.5.2Corrective ActionInvestigation, root cause, effectiveness
8.5.3Preventive ActionRisk identification, implementation, verification

Document Control Workflow

Establish and maintain document control per ISO 13485 Clause 4.2.3.

Workflow: Document Creation and Approval

  1. Identify need for new document or revision
  2. Assign document number per numbering convention:
    • Format:
      [TYPE]-[AREA]-[SEQUENCE]-[REV]
    • Example:
      SOP-02-001-01
  3. Draft document using approved template
  4. Route for review to subject matter experts
  5. Collect and address review comments
  6. Obtain required approvals based on document type
  7. Update Document Master List
  8. Validation: Document numbered correctly; all reviewers signed; Master List updated

Document Numbering Convention

PrefixDocument TypeApproval Authority
QMQuality ManualManagement Rep + CEO
POLPolicyDepartment Head + QA
SOPProcedureProcess Owner + QA
WIWork InstructionSupervisor + QA
TFTemplate/FormProcess Owner
SPECSpecificationEngineering + QA

Area Codes

CodeAreaExamples
01Quality ManagementQuality Manual, policy
02Document ControlThis procedure
03TrainingCompetency procedures
04DesignDesign control
05PurchasingSupplier management
06ProductionManufacturing
07Quality ControlInspection, testing
08CAPACorrective actions

Document Change Control

Change TypeApproval LevelExamples
AdministrativeDocument ControlTypos, formatting
MinorProcess Owner + QAClarifications
MajorFull review cycleProcess changes
EmergencyExpedited + retrospectiveSafety issues

Document Review Schedule

Document TypeReview PeriodTrigger for Unscheduled Review
Quality ManualAnnualOrganizational change
ProceduresAnnualAudit finding, regulation change
Work Instructions2 yearsProcess change
Forms2 yearsUser feedback

Internal Audit Workflow

Plan and execute internal audits per ISO 13485 Clause 8.2.4.

Workflow: Annual Audit Program

  1. Identify processes and areas requiring audit coverage
  2. Assess risk factors for audit frequency:
    • Previous audit findings
    • Regulatory changes
    • Process changes
    • Complaint trends
  3. Assign qualified auditors (independent of area audited)
  4. Develop annual audit schedule
  5. Obtain management approval
  6. Communicate schedule to process owners
  7. Track completion and reschedule as needed
  8. Validation: All processes covered; auditors qualified and independent; schedule approved

Workflow: Individual Audit Execution

  1. Prepare audit plan with scope, criteria, and schedule
  2. Notify auditee minimum 1 week prior
  3. Review procedures and previous audit results
  4. Prepare audit checklist
  5. Conduct opening meeting
  6. Collect evidence through:
    • Document review
    • Record sampling
    • Process observation
    • Personnel interviews
  7. Classify findings:
    • Major NC: Absence or breakdown of system
    • Minor NC: Single lapse or deviation
    • Observation: Risk of future NC
  8. Conduct closing meeting
  9. Issue audit report within 5 business days
  10. Validation: All checklist items addressed; findings supported by evidence; report distributed

Audit Program Template

Audit #ProcessClausesQ1Q2Q3Q4Auditor
IA-001Document Control4.2.3, 4.2.4X[Name]
IA-002Management Review5.6X[Name]
IA-003Design Control7.3X[Name]
IA-004Production7.5X[Name]
IA-005CAPA8.5.2, 8.5.3X[Name]

Auditor Qualification Requirements

CriterionRequirement
TrainingISO 13485 awareness + auditor training
ExperienceMinimum 1 audit as observer
IndependenceNot auditing own work area
CompetenceUnderstanding of audited process

Finding Classification Guide

ClassificationCriteriaResponse Time
Major NCSystem absence, total breakdown, regulatory violation30 days for CAPA
Minor NCSingle instance, partial compliance60 days for CAPA
ObservationPotential risk, improvement opportunityTrack in next audit

Process Validation Workflow

Validate special processes per ISO 13485 Clause 7.5.6.

Workflow: Process Validation Protocol

  1. Identify processes requiring validation:
    • Output cannot be verified by inspection
    • Deficiencies appear only in use
    • Sterilization, welding, sealing, software
  2. Form validation team with subject matter experts
  3. Write validation protocol including:
    • Process description and parameters
    • Equipment and materials
    • Acceptance criteria
    • Statistical approach
  4. Execute Installation Qualification (IQ):
    • Verify equipment installed correctly
    • Document equipment specifications
  5. Execute Operational Qualification (OQ):
    • Test parameter ranges
    • Verify process control
  6. Execute Performance Qualification (PQ):
    • Run production conditions
    • Verify output meets requirements
  7. Write validation report with conclusions
  8. Validation: IQ/OQ/PQ complete; acceptance criteria met; validation report approved

Validation Documentation Requirements

PhaseContentEvidence
ProtocolObjectives, methods, criteriaApproved protocol
IQEquipment verificationInstallation records
OQParameter verificationTest results
PQPerformance verificationProduction data
ReportSummary, conclusionsApproval signatures

Revalidation Triggers

TriggerAction Required
Equipment changeAssess impact, revalidate affected phases
Parameter changeOQ and PQ minimum
Material changeAssess impact, PQ minimum
Process failureFull revalidation
PeriodicPer validation schedule (typically 3 years)

Special Process Examples

ProcessValidation StandardCritical Parameters
EO SterilizationISO 11135Temperature, humidity, EO concentration, time
Steam SterilizationISO 17665Temperature, pressure, time
Radiation SterilizationISO 11137Dose, dose uniformity
SealingInternalTemperature, pressure, dwell time
WeldingISO 11607Heat, pressure, speed

Supplier Qualification Workflow

Evaluate and approve suppliers per ISO 13485 Clause 7.4.

Workflow: New Supplier Qualification

  1. Identify supplier category:
    • Category A: Critical (affects safety/performance)
    • Category B: Major (affects quality)
    • Category C: Minor (indirect impact)
  2. Request supplier information:
    • Quality certifications
    • Product specifications
    • Quality history
  3. Evaluate supplier based on:
    • Quality system (ISO certification)
    • Technical capability
    • Quality history
    • Financial stability
  4. For Category A suppliers:
    • Conduct on-site audit
    • Require quality agreement
  5. Calculate qualification score
  6. Make approval decision:
    • 80: Approved

    • 60-80: Conditional approval
    • <60: Not approved
  7. Add to Approved Supplier List
  8. Validation: Evaluation criteria scored; qualification records complete; supplier categorized

Supplier Evaluation Criteria

CriterionWeightScoring
Quality System30%ISO 13485=30, ISO 9001=20, Documented=10, None=0
Quality History25%Reject rate: <1%=25, 1-3%=15, >3%=0
Delivery20%On-time: >95%=20, 90-95%=10, <90%=0
Technical Capability15%Exceeds=15, Meets=10, Marginal=5
Financial Stability10%Strong=10, Adequate=5, Questionable=0

Supplier Category Requirements

CategoryQualificationMonitoringAgreement
A - CriticalOn-site auditAnnual reviewQuality agreement
B - MajorQuestionnaireSemi-annual reviewQuality requirements
C - MinorAssessmentIssue-basedStandard terms

Supplier Performance Metrics

MetricTargetCalculation
Accept Rate>98%(Accepted lots / Total lots) × 100
On-Time Delivery>95%(On-time / Total orders) × 100
Response Time<5 daysAverage days to resolve issues
Documentation100%(Complete CoCs / Required CoCs) × 100

QMS Process Reference

ISO 13485 Clause Structure

ClauseTitleKey Requirements
4.1General RequirementsProcess identification, interaction, outsourcing
4.2DocumentationQuality Manual, procedures, records
5.1-5.5Management ResponsibilityCommitment, policy, objectives, organization
5.6Management ReviewInputs, outputs, records
6.1-6.4Resource ManagementPersonnel, infrastructure, environment
7.1Product Realization PlanningQuality plan, risk management
7.2Customer RequirementsDetermination, review, communication
7.3Design and DevelopmentPlanning, inputs, outputs, review, V&V, transfer, changes
7.4PurchasingSupplier control, purchasing info, verification
7.5ProductionControl, cleanliness, validation, identification, traceability
7.6Monitoring EquipmentCalibration, control
8.1Measurement PlanningMonitoring and analysis planning
8.2MonitoringFeedback, complaints, reporting, audits, process, product
8.3Nonconforming ProductControl, disposition
8.4Data AnalysisTrend analysis
8.5ImprovementCAPA

Management Review Required Inputs (Clause 5.6.2)

InputSourcePrepared By
Audit resultsInternal and external auditsQA Manager
Customer feedbackComplaints, surveysCustomer Quality
Process performanceProcess metricsProcess Owners
Product conformityInspection data, NCsQC Manager
CAPA statusCAPA systemCAPA Officer
Previous actionsPrior review recordsQMR
Changes affecting QMSRegulatory, organizationalRA Manager
RecommendationsAll sourcesAll Managers

Record Retention Requirements

Record TypeMinimum RetentionRegulatory Basis
Device Master RecordLife of device + 2 years21 CFR 820.181
Device History RecordLife of device + 2 years21 CFR 820.184
Design History FileLife of device + 2 years21 CFR 820.30
Complaint RecordsLife of device + 2 years21 CFR 820.198
Training RecordsEmployment + 3 yearsBest practice
Audit Records7 yearsBest practice
CAPA Records7 yearsBest practice
Calibration RecordsEquipment life + 2 yearsBest practice

Decision Frameworks

Exclusion Justification (Clause 4.2.2)

ClausePermissible ExclusionJustification Required
6.4.2Contamination controlProduct not affected by contamination
7.3Design and developmentOrganization does not design products
7.5.2Product cleanlinessNo cleanliness requirements
7.5.3InstallationNo installation activities
7.5.4ServicingNo servicing activities
7.5.5Sterile productsNo sterile products

Nonconformity Disposition Decision Tree

Nonconforming Product Identified
            │
            ▼
    Can it be reworked?
            │
       Yes──┴──No
        │       │
        ▼       ▼
    Is rework     Can it be used
    procedure     as is?
    available?        │
        │        Yes──┴──No
    Yes─┴─No     │       │
     │    │     ▼       ▼
     ▼    ▼  Concession  Scrap or
  Rework  Create    approval    return to
  per SOP  rework    needed?    supplier
          procedure     │
                    Yes─┴─No
                     │    │
                     ▼    ▼
                 Customer  Use as is
                 approval  with MRB
                          approval

CAPA Initiation Criteria

SourceAutomatic CAPAEvaluate for CAPA
Customer complaintSafety-relatedAll others
External auditMajor NCMinor NC
Internal auditMajor NCRepeat minor NC
Product NCField failureTrend exceeds threshold
Process deviationSafety impactRepeated deviations

Tools and References

Scripts

ToolPurposeUsage
qms_audit_checklist.pyGenerate audit checklists by clause or process
python qms_audit_checklist.py --help

Audit Checklist Generator Features:

  • Generate clause-specific checklists (e.g.,
    --clause 7.3
    )
  • Generate process-based checklists (e.g.,
    --process design-control
    )
  • Full system audit checklist (
    --audit-type system
    )
  • Text or JSON output formats
  • Interactive mode for guided selection

References

DocumentContent
iso13485-clause-requirements.mdDetailed requirements for each ISO 13485:2016 clause with audit questions
qms-process-templates.mdReady-to-use templates for document control, audit, CAPA, supplier, training

Quick Reference: Mandatory Documented Procedures

ProcedureClauseKey Elements
Document Control4.2.3Approval, distribution, obsolete control
Record Control4.2.4Identification, retention, disposal
Internal Audit8.2.4Program, auditor qualification, reporting
NC Product Control8.3Identification, segregation, disposition
Corrective Action8.5.2Root cause, implementation, verification
Preventive Action8.5.3Risk identification, implementation

Related Skills

SkillIntegration Point
quality-manager-qmrManagement review, quality policy
capa-officerCAPA system management
qms-audit-expertAdvanced audit techniques
quality-documentation-managerDHF, DMR, DHR management
risk-management-specialistISO 14971 integration

ISO 13485:2016 Alignment with FDA QMSR

QMSR Transition Impact on ISO 13485 QMS

With the FDA's QMSR (effective February 2, 2026) incorporating ISO 13485:2016 by reference, organizations already ISO 13485 certified gain significant advantages:

AreaPre-QMSR (Dual System)Post-QMSR (Unified)
Quality ManualSeparate FDA QSR and ISO 13485 referencesSingle Quality Manual referencing ISO 13485
Design controls820.30 + ISO 13485 Clause 7.3 (mapped)ISO 13485 Clause 7.3 (primary)
CAPA820.100 + ISO 13485 Clause 8.5ISO 13485 Clause 8.5 (primary)
Document control820.40 + ISO 13485 Clause 4.2ISO 13485 Clause 4.2 (primary)
Purchasing820.50 + ISO 13485 Clause 7.4ISO 13485 Clause 7.4 (primary)
AuditsSeparate FDA and ISO audit tracksSingle audit satisfying both

FDA-Retained Requirements Beyond ISO 13485

Even under QMSR, certain FDA-specific requirements remain. The QMS must address:

FDA RequirementCFR ReferenceISO 13485 GapAction
Complaint handling (medical device reports)21 CFR 820.198Clause 8.2.2 covers complaints but not FDA MDR reporting specificsAdd FDA MDR reporting procedure to complaint handling SOP
Corrections and removals21 CFR 806No direct equivalentMaintain separate procedure for FDA reporting of corrections/removals
Unique Device Identification21 CFR 830No UDI clause in ISO 13485Add UDI procedures to labeling/identification processes
Electronic records and signatures21 CFR Part 11No electronic signature requirementsImplement Part 11 compliance for electronic QMS

QMSR Gap Analysis Checklist

  • Map all existing QSR SOPs to ISO 13485 clause numbers
  • Identify FDA-retained requirements not covered by ISO 13485
  • Update Quality Manual scope and references
  • Retrain staff on ISO 13485 terminology (e.g., "design output" terminology alignment)
  • Update supplier quality agreements to reference QMSR
  • Revise internal audit checklist to combined ISO 13485 + FDA requirements
  • Verify complaint handling addresses both ISO 13485 Clause 8.2.2 and 21 CFR 820.198
  • Conduct mock audit against QMSR requirements

Digital QMS Implementation

Electronic Document Management System (eDMS) Requirements

RequirementImplementationRegulatory Basis
Document version controlAutomatic versioning with audit trailISO 13485 Clause 4.2.3
Electronic approval workflowsRole-based approval routing with e-signatures21 CFR Part 11, Annex 11
Access controlsRole-based permissions, segregation of dutiesISO 13485 Clause 4.2.3(c)
Audit trailImmutable record of all changes with timestamp, user, reason21 CFR Part 11 §11.10(e)
Backup and recoveryRegular backups with tested restore proceduresISO 13485 Clause 4.2.4
Training records integrationLink document access to training completionISO 13485 Clause 6.2
Obsolete document controlAutomatic removal from use with archivalISO 13485 Clause 4.2.3(e)

Electronic Signatures

Signature TypeUse CaseTechnical Requirement
Electronic signatureDocument approval, batch release, CAPA closureLinked to individual, date/time stamped, meaning included
Digital signatureHigh-assurance: design reviews, regulatory submissionsPKI-based, certificate authority, tamper-evident
Biometric signatureOptional for high-security processesFingerprint or similar biometric linked to identity

Audit Trail Requirements

ElementDescriptionExample
WhoUser identity (not shared accounts)jane.smith@company.com
WhatAction performed"Approved SOP-02-001 Rev 3"
WhenDate and time (UTC or with timezone)2026-03-09T14:30:00Z
WhyReason for change (required for modifications)"Updated per CAPA-2026-003 findings"
Previous valueOld content (for modifications)Automatic diff/version comparison

Cross-Reference: 21 CFR Part 11 / Annex 11

21 CFR Part 11 Requirements for Electronic Records

RequirementSectionQMS Implementation
Validation§11.10(a)Validate eQMS software per GAMP 5 methodology
Audit trail§11.10(e)Computer-generated, timestamped, immutable audit trail
System access controls§11.10(d)Unique user IDs, passwords, role-based access
Authority checks§11.10(g)Only authorized individuals can use specific functions
Device checks§11.10(h)Verify source of data input
Personnel qualification§11.10(i)Training on system use and Part 11 requirements
Electronic signatures§11.50, §11.100Unique to individual, not reusable, linked to records
Open vs. closed systems§11.30 vs. §11.10Determine system type; open systems need encryption

Annex 11 (EU GMP) Requirements

RequirementSectionQMS Implementation
Risk management§1Apply risk-based approach to computerized system validation
Personnel§2Designated system owner and trained users
Supplier assessment§3Assess eQMS vendor quality and compliance capability
Validation§4-5IQ/OQ/PQ for eQMS, validation plan and report
Data§6-9Data integrity, accuracy checks, data storage
Printouts§8Ability to generate clear, legible copies of electronic records
Audit trail§9Record of all GMP-relevant changes
Change and configuration management§10-11Controlled change process for system modifications
Security§12Physical and logical security controls
Incident management§13Procedure for reporting and managing system incidents
Electronic signatures§14Equivalent legal standing to handwritten signatures
Batch release§15Electronic batch release with appropriate controls
Business continuity§16Contingency procedures for system unavailability
Archiving§17Long-term accessibility and readability of archived data

Remote Audit Considerations (Post-COVID)

Remote Audit Methodology

Audit ElementOn-Site ApproachRemote Equivalent
Document reviewPhysical review of controlled copiesScreen-sharing of eDMS, live navigation
Record samplingPull physical records from filesLive database queries via screen-share
Process observationWalk the production floorLive video tour, camera-equipped devices
Personnel interviewsFace-to-faceVideo conference with individual sessions
Equipment verificationPhysical inspectionLive video with zoom capability
Evidence collectionPhotocopies, photographsScreenshots, screen recordings, exported PDFs

Remote Audit Best Practices

PracticeDescription
Pre-audit documentationShare document packages 2 weeks before audit via secure portal
Technology testingTest video conferencing, screen-sharing, and secure file transfer before audit
Audit plan adaptationAllow 20-30% more time for remote activities vs. on-site
Secure communicationUse encrypted channels for all audit communications and evidence transfer
Real-time evidencePrefer live demonstrations over pre-recorded material
Breakout roomsUse separate video sessions for confidential interviews
Audit trail of the auditRecord audit sessions (with agreement) for reference

Hybrid Audit Model

ActivityRecommended ModeRationale
Opening/closing meetingsRemoteEfficient, schedule-friendly
Document and record reviewRemoteFull eDMS access, efficient sampling
Process observation (manufacturing)On-siteCannot verify physical processes remotely
Cleanroom/controlled environmentOn-siteEnvironmental conditions require physical presence
Software system reviewRemoteScreen-sharing is equivalent or better
Management interviewEitherRemote is acceptable
Supplier audit (critical)On-sitePhysical verification essential

Cross-Reference: ISO 42001 for AI-Enabled Medical Devices

ISO 42001 (AI Management System) Integration with ISO 13485

For medical device organizations developing AI-enabled products, ISO 42001:2023 provides an AI management system framework:

ISO 42001 ClauseISO 13485 Integration PointCombined Requirement
4. Context of the organizationClause 4.1 (General requirements)Extend QMS scope to include AI-specific processes
5. LeadershipClause 5 (Management responsibility)AI governance within quality policy and objectives
6. Planning (AI risk assessment)Clause 7.1 (Risk management planning)Extend ISO 14971 risk management to AI-specific risks
7. Support (AI competence)Clause 6.2 (Human resources)Add AI/ML competency requirements to training matrix
8. Operation (AI lifecycle)Clause 7.3 (Design and development)Integrate AI development lifecycle into design controls
9. Performance evaluationClause 8 (Measurement, analysis)Add AI performance metrics to quality monitoring
10. ImprovementClause 8.5 (CAPA)Include AI-related incidents in CAPA scope

AI Lifecycle Integration with Design Controls

ISO 13485 Design Control (Cl. 7.3)     ISO 42001 AI Lifecycle
─────────────────────────────────       ─────────────────────
Design Input (7.3.3)                    AI System Requirements
    ↓                                       ↓
Design Output (7.3.4)                   Data Collection & Preparation
    ↓                                   Model Architecture & Training
    ↓                                       ↓
Design Review (7.3.5)                   AI Model Validation Review
    ↓                                       ↓
Design Verification (7.3.6)            Model Verification (accuracy, bias)
    ↓                                       ↓
Design Validation (7.3.7)             Clinical Validation (real-world performance)
    ↓                                       ↓
Design Transfer (7.3.8)               Model Deployment & Monitoring
    ↓                                       ↓
Design Changes (7.3.9)                Model Retraining & Update Control

Supplier Qualification for Software/Cloud Providers

Cloud Service Provider Qualification

Qualification CriterionAssessment MethodMinimum Requirement
Information securityISO 27001 certificate or SOC 2 Type II reportCurrent certification for relevant scope
Data residencyContractual agreement + architecture reviewData stored in jurisdictions compliant with regulations
Availability SLAService agreement review99.9% uptime minimum for critical systems
Backup and recoveryArchitecture review + test resultsRPO < 4 hours, RTO < 8 hours for critical systems
Incident notificationContract clause reviewNotification within 24 hours of security incident
Audit rightsContract clauseRight to audit or receive audit reports
Regulatory complianceVendor compliance documentationGxP-qualified environments (if applicable)
Exit strategyData portability assessmentDocumented data export capability in standard formats

Software Supplier Assessment

Assessment AreaCategory A (Critical)Category B (Major)Category C (Minor)
Quality systemISO 13485 or ISO 9001 requiredISO 9001 preferredDocumented processes
Development processIEC 62304 compliance evidenceSDLC documentationBasic version control
CybersecurityIEC 81001-5-1 complianceSecurity testing evidenceBasic security practices
Change managementFormal change control with notificationRelease notes and notificationVersion tracking
Validation supportIQ/OQ/PQ documentation providedFunctional test documentationUser documentation
Incident handlingSLA-based response with root causeDefined support processBest-effort support

CAPA Integration with Cybersecurity Incidents

Cybersecurity Incident as CAPA Trigger

Incident TypeCAPA Required?Response Actions
Patient data breachYes — automaticContain → investigate → notify (GDPR 72h, HIPAA 60 days) → CAPA
Device vulnerability (exploitable)Yes — automaticPatch → verify → communicate → CAPA for root cause
Device vulnerability (not exploitable)EvaluateRisk assessment → mitigate if feasible → track
Malware on manufacturing systemYes — automaticIsolate → clean → verify product integrity → CAPA
Unauthorized access to QMSYes — automaticRevoke access → assess impact → verify record integrity → CAPA
Supplier security incidentEvaluateAssess impact on device/data → CAPA if product affected

Cybersecurity CAPA Process

Step 1: Incident Detection and Containment
        → Activate incident response plan
        → Contain threat and preserve evidence
        → Assess impact on product safety and quality

Step 2: Investigation (Root Cause Analysis)
        → Technical forensic analysis
        → 5 Whys + attack chain reconstruction
        → Identify QMS process failures that enabled the incident
        → Assess whether product quality was affected

Step 3: Corrective Actions
        → Technical: patch vulnerability, update security controls
        → Process: update SOPs, access controls, monitoring
        → People: security awareness training
        → Product: assess need for field safety corrective action (FSCA)

Step 4: Preventive Actions
        → Threat modeling review for similar attack vectors
        → Security control gap analysis
        → Supply chain security review (if applicable)
        → Update cybersecurity risk assessment

Step 5: Effectiveness Verification
        → Penetration testing to verify fix
        → Monitoring for recurrence (90-day window)
        → Review of updated security metrics
        → Close CAPA with evidence of effectiveness

Step 6: Regulatory Reporting (if required)
        → MDR vigilance report (if patient safety affected)
        → FDA MedWatch report (if applicable)
        → GDPR breach notification (if personal data involved)
        → NIS2 incident report (if essential entity)

Cross-references: See

../information-security-manager-iso27001/SKILL.md
for ISO 27001 incident response procedures,
../fda-consultant-specialist/SKILL.md
for FDA QMSR alignment, and
../risk-management-specialist/SKILL.md
for cybersecurity risk integration with ISO 14971.


ISO 13485 Enhanced — QMSR, Digital QMS & Cross-Framework Integration

ISO 13485:2016 Alignment with FDA QMSR

With FDA's Quality Management System Regulation (QMSR) effective Feb 2026:

  • Direct Alignment: FDA now recognizes ISO 13485:2016 as the quality system standard
  • Single QMS: Organizations can maintain one QMS for both FDA and EU market access
  • Gap Analysis: Identify differences between current QSR procedures and ISO 13485 requirements
  • Transition Plan: Map QSR 21 CFR 820 sections to ISO 13485 clauses, update procedures
  • Cross-reference: See
    fda-consultant-specialist
    for detailed FDA requirements

Digital QMS Implementation

  • Electronic Document Control: Validated electronic document management system (eDMS)
  • Electronic Signatures: 21 CFR Part 11 / EU Annex 11 compliant e-signatures
  • Audit Trail: Automated, timestamped, immutable record of all document changes
  • Cloud QMS Platforms: Qualification requirements for SaaS QMS solutions (IQ/OQ/PQ)
  • Cross-reference: See
    quality-documentation-manager
    for Part 11 compliance

Remote Audit Considerations

  • Hybrid Audits: Combination of on-site and remote activities (ISO 19011 guidance)
  • Technology Requirements: Secure video conferencing, screen sharing, document access
  • Limitations: Physical process observations may require on-site verification
  • Notified Body Acceptance: Most NBs accept hybrid audits for surveillance and recertification

AI-Enabled Medical Device QMS

  • ISO 42001 Integration: For organizations developing AI-enabled medical devices
  • Data Governance: Training data quality per ISO 42001 Annex A.7 within QMS
  • Model Lifecycle: AI model versioning and change control within existing QMS processes
  • Cross-reference: See
    iso42001-ai-management
    for AI management system requirements

Supplier Qualification for Software/Cloud Providers

  • Cloud Service Providers: Qualification checklist (SOC 2, ISO 27001, data residency, SLAs)
  • Open Source Software: Risk assessment for OSS components (licensing, maintenance, vulnerabilities)
  • SaaS Tools: Validation requirements for SaaS platforms used in QMS processes
  • SBOM Management: Track software components across the supply chain

Troubleshooting

ProblemLikely CauseResolution
Audit checklist generator returns empty outputClause number not recognizedUse exact clause numbers from ISO 13485:2016 (e.g.,
7.3
,
4.2.3
,
8.5.2
). Run with
--interactive
to see all available clauses.
System audit checklist is very large
--audit-type system
includes all clauses
For targeted audits, use
--clause
or
--process
flags to generate focused checklists. System audits intentionally cover the full standard.
Gap analysis matrix shows all clauses as "Major" gapsAssessment conducted against a greenfield organizationPrioritize gaps by regulatory criticality and product safety impact. Address Clauses 4.2, 7.3, 8.2.4, 8.3, and 8.5 first as these require mandatory documented procedures.
QMSR transition mapping unclearQSR sections not aligned to ISO 13485 clausesThe QMSR (effective Feb 2, 2026) incorporates ISO 13485 by reference. Map QSR 21 CFR 820 sub-parts to ISO 13485 clauses using the QMSR Gap Analysis Checklist in this skill.
Supplier qualification score borderline (60-80)Supplier meets some criteria but has gapsIssue conditional approval with documented improvement requirements and a defined reassessment date. Increase monitoring frequency until the supplier exceeds the 80-point threshold.
Process validation protocol incompleteIQ/OQ/PQ phases not clearly separatedEach qualification phase must have distinct objectives, acceptance criteria, and documented results. Use the Validation Documentation Requirements table as a template for protocol structure.
Design control audit questions not applicableOrganization does not perform design activitiesISO 13485 permits exclusion of Clause 7.3 if the organization does not design products. Document the exclusion justification in the Quality Manual per Clause 4.2.2.

Success Criteria

  • QMS gap analysis completed against all ISO 13485:2016 clauses with documented current state, gap severity, priority, and remediation actions
  • All 6 mandatory documented procedures established, trained, and effective (document control, record control, internal audit, NC product, corrective action, preventive action)
  • Quality Manual approved with justified clause exclusions, process interactions documented, and scope clearly defined
  • QMSR transition completed: all QSR SOPs mapped to ISO 13485 clauses, FDA-retained requirements addressed, internal audit checklist updated for combined ISO 13485 + FDA requirements
  • Supplier qualification program operational with category-based assessment (A/B/C), documented scoring, and approved supplier list maintained
  • Process validation completed for all special processes (IQ/OQ/PQ documented with approved protocols and reports)
  • Certification audit passed with zero Major nonconformities and a plan to address any Minor findings within 60 days

Scope & Limitations

In Scope:

  • ISO 13485:2016 QMS implementation from gap analysis through certification
  • Document control system design (numbering, approval, change control, review schedules)
  • Internal audit program planning and execution per Clause 8.2.4
  • Process validation methodology (IQ/OQ/PQ) per Clause 7.5.6
  • Supplier qualification and monitoring per Clause 7.4
  • FDA QMSR transition planning and gap analysis
  • Digital QMS implementation (eDMS, Part 11, Annex 11 requirements)
  • Remote and hybrid audit methodology
  • AI-enabled medical device QMS considerations (ISO 42001 integration)

Out of Scope:

  • Clinical evaluation or clinical investigation management (use regulatory-affairs-head for clinical evidence strategy)
  • Product-specific design control execution (the skill provides the design control framework, not product-specific design inputs/outputs)
  • Sterilization validation protocol development (requires product-specific expertise per ISO 11135/11137/17665)
  • Regulatory submission preparation (use fda-consultant-specialist or mdr-745-specialist)
  • Post-market surveillance program execution (use risk-management-specialist for post-production risk monitoring)
  • IT infrastructure or cybersecurity implementation (use infrastructure-compliance-auditor for technical security)

Integration Points

SkillIntegration
quality-manager-qmrQMR oversees QMS effectiveness; management review inputs include QMS process performance metrics
capa-officerCAPA system (Clause 8.5) is a core QMS process; CAPA effectiveness feeds into management review
qms-audit-expertInternal audit program (Clause 8.2.4) evaluates QMS processes; audit findings drive CAPA and improvement
quality-documentation-managerDocument and record control (Clause 4.2) provides the documentation foundation for the entire QMS
risk-management-specialistISO 14971 risk management integrates with design control (Clause 7.3) and product realization planning (Clause 7.1)
fda-consultant-specialistQMSR alignment requires mapping FDA-specific requirements (MDR reporting, UDI, Part 11) beyond ISO 13485
regulatory-affairs-headRegulatory strategy informs QMS scope, market-specific requirements, and certification timelines

Tool Reference

qms_audit_checklist.py

Generates ISO 13485:2016 audit checklists by clause, process, or full system audit.

FlagRequiredDescription
--clause
NoISO 13485 clause number to generate a clause-specific checklist (e.g.,
7.3
,
4.2.3
,
8.5.2
)
--process
NoProcess name for a process-based checklist (e.g.,
design-control
,
purchasing
,
capa
)
--audit-type
NoAudit type:
system
for a full-system checklist covering all clauses
--output
NoOutput format:
json
for structured output, omit for human-readable text
--interactive
NoLaunch interactive mode for guided clause/process selection