Medical Devices Quality Management Systems
International standard specifying requirements for quality management systems for medical device manufacturers. Required for CE marking and FDA approval processes.
What ISO 13485 draws on
This framework pulls on 2 pillars of the platform.
Compliance
- Sensitive Data DiscoveryFinds and classifies the regulated data, so everything downstream knows what is in scope.
- Policy & ComplianceTurns the captured activity into the report shape the framework asks for.
- Compliance Advisory ServicesOrganises the gap register, the remediation roadmap, and the auditor-ready pack.
What your auditor cites,
and what produces the evidence
The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.
Control of Documents
Organizations MUST establish documented procedures to define controls needed for approval, review, updating, and identification of documents.
This mandate asks for documented policy and procedure rather than telemetry, so the platform is the evidence layer beneath it rather than the control itself. Our advisory engagements organise that documentation — a gap register mapping each requirement to its current state and a named owner, a sequenced remediation roadmap, and quarterly auditor-ready packs — and we answer the database-controls questions during the audit window. Drafting and owning the policy stays with you; assembling the evidence that it operates does not have to.
Control of Records
Records MUST remain legible, readily identifiable, and retrievable. Retention times MUST be established.
Retention obligations are easy to state and expensive to meet, because the cost is in keeping the record queryable rather than merely stored. Audit events land in columnar storage on immutable object storage, so a multi-year window costs object-storage prices and is still searchable in seconds when an examiner asks for a sample. Each record carries a verification hash, so what you produce years later is demonstrably what was written at the time.
Control of Production
Production processes MUST be validated and controlled with documented procedures and traceability.
This mandate asks for documented policy and procedure rather than telemetry, so the platform is the evidence layer beneath it rather than the control itself. Our advisory engagements organise that documentation — a gap register mapping each requirement to its current state and a named owner, a sequenced remediation roadmap, and quarterly auditor-ready packs — and we answer the database-controls questions during the audit window. Drafting and owning the policy stays with you; assembling the evidence that it operates does not have to.
Monitoring and Measurement
Organization MUST monitor and measure product characteristics to verify requirements have been met.
A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.
What ISO 13485 covers
This instrument defines no data category of its own. Governs the quality management SYSTEM for medical devices. Records are defined by process — design history, device master record — rather than by data class.
How ISO 13485 is enforced
Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by Your notified body or certification body, at surveillance audits.
A voluntary standard. No regulator enforces it.
ISO 13485 is voluntary as a standard, yet in practice it is the route by which a device manufacturer demonstrates a quality management system to a notified body. Suspension of the certificate suspends the CE marking that depends on it, which stops sales.
The standard is voluntary; the regulation that relies on it is not. The consequence you feel comes from the latter.
Uncapped exposure that sits outside this instrument
These come from company law rather than from ISO 13485, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.
Duty of oversight
Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.
Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.
Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.
This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.
In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).
Enforcement data reviewed August 2026. Several figures are indexed annually and move.
Built for ISO 13485,
not configured for it afterwards
Medical Device Data Traceability
Track all software-driven medical device database outputs
ISO 13485 Audit Evidence
Full lifecycle auditability documentation for certification
Device Master Records
Identify DMR, DHR, and device-related production data
Quality Record Modification
Alert on changes to quality management records
Other Healthcare frameworks
Walk into the ISO 13485 audit knowing the answer
228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.