ISO 13485HealthcareGlobalMedical Devices

Medical Devices Quality Management Systems

International standard specifying requirements for quality management systems for medical device manufacturers. Required for CE marking and FDA approval processes.

Get a Gap Assessment
The Mapping

What your auditor cites,
and what produces the evidence

The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.

ISO 13485§4.2.5Policy, procedure, and documentation

Control of Documents

Organizations MUST establish documented procedures to define controls needed for approval, review, updating, and identification of documents.

This mandate asks for documented policy and procedure rather than telemetry, so the platform is the evidence layer beneath it rather than the control itself. Our advisory engagements organise that documentation — a gap register mapping each requirement to its current state and a named owner, a sequenced remediation roadmap, and quarterly auditor-ready packs — and we answer the database-controls questions during the audit window. Drafting and owning the policy stays with you; assembling the evidence that it operates does not have to.

ISO 13485§4.2.4Retention and availability

Control of Records

Records MUST remain legible, readily identifiable, and retrievable. Retention times MUST be established.

Retention obligations are easy to state and expensive to meet, because the cost is in keeping the record queryable rather than merely stored. Audit events land in columnar storage on immutable object storage, so a multi-year window costs object-storage prices and is still searchable in seconds when an examiner asks for a sample. Each record carries a verification hash, so what you produce years later is demonstrably what was written at the time.

ISO 13485§7.5.1Policy, procedure, and documentation

Control of Production

Production processes MUST be validated and controlled with documented procedures and traceability.

This mandate asks for documented policy and procedure rather than telemetry, so the platform is the evidence layer beneath it rather than the control itself. Our advisory engagements organise that documentation — a gap register mapping each requirement to its current state and a named owner, a sequenced remediation roadmap, and quarterly auditor-ready packs — and we answer the database-controls questions during the audit window. Drafting and owning the policy stays with you; assembling the evidence that it operates does not have to.

ISO 13485§8.2.4A record of access

Monitoring and Measurement

Organization MUST monitor and measure product characteristics to verify requirements have been met.

A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.

What ISO 13485 covers

This instrument defines no data category of its own. Governs the quality management SYSTEM for medical devices. Records are defined by process — design history, device master record — rather than by data class.

How ISO 13485 is enforced

Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by Your notified body or certification body, at surveillance audits.

A voluntary standard. No regulator enforces it.

ISO 13485 is voluntary as a standard, yet in practice it is the route by which a device manufacturer demonstrates a quality management system to a notified body. Suspension of the certificate suspends the CE marking that depends on it, which stops sales.

The standard is voluntary; the regulation that relies on it is not. The consequence you feel comes from the latter.

Uncapped exposure that sits outside this instrument

These come from company law rather than from ISO 13485, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.

Duty of oversight

Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.

Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.

Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.

This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.

In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).

Enforcement data reviewed August 2026. Several figures are indexed annually and move.

Ships With It

Built for ISO 13485,
not configured for it afterwards

Policy Template

Medical Device Data Traceability

Track all software-driven medical device database outputs

Report

ISO 13485 Audit Evidence

Full lifecycle auditability documentation for certification

Classification

Device Master Records

Identify DMR, DHR, and device-related production data

Alert

Quality Record Modification

Alert on changes to quality management records

Walk into the ISO 13485 audit knowing the answer

228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.

Get a Gap Assessment