Quality documentation manager

Document control system management for medical device QMS.

How to use it

Claude Code
  1. Run the line below. It pulls the whole folder into ~/.claude/skills/quality-documentation-manager, including the files SKILL.md points to.
  2. Describe your job in plain words. Claude Code follows the skill from there.
Claude Code — installs the whole folder, not just SKILL.md
npx degit alirezarezvani/claude-skills/ra-qm-team/skills/quality-documentation-manager#main ~/.claude/skills/quality-documentation-manager

For one project only, change the path to .claude/skills/quality-documentation-manager. This skill also uses document.json, sample_doc.json — copying SKILL.md alone won't be enough. See the folder on GitHub.

Claude (web or desktop app)
  1. On this page open ⋯ → Download .md.
  2. Save it as SKILL.md in a folder, zip the folder, then Customize → Skills → + → Create skill → Upload a skill.
  3. Pick the file and Save. Claude shows the name and description and runs a security scan.
  4. Check the skill is switched on.
  5. Start a new chat and describe your job in plain words. The AI follows the skill from there.
ChatGPT or another app
  1. ChatGPT: make a Project and paste it into Instructions.
  2. Neither? Paste it at the top of a new chat — it works for that chat.
Not working?
  • Check which app you pasted it into — the steps above name the right one.
  • Some skills need the paid tier of Claude or ChatGPT.
Step-by-step guide with screenshots · Ask in the forum

Paste into Claude, ChatGPT or Cursor.

Source of Quality documentation manager

Show the full text442 lines
namedescriptiontriggers
quality-documentation-managerDocument control system management for medical device QMS. Covers document numbering, version control, change management, and 21 CFR Part 11 compliance. Use when working on document control procedures, change control workflows, document numbering, version management, electronic signature compliance, or regulatory documentation review. - document control - document numbering - version control - change control - document approval - electronic signature - 21 CFR Part 11 - audit trail - document lifecycle - controlled document - document master list - record retention

Quality Documentation Manager

Document control system design and management for ISO 13485-compliant quality management systems, including numbering conventions, approval workflows, change control, and electronic record compliance.


Table of Contents


Document Control Workflow

Implement document control from creation through obsolescence:

  1. Assign document number per numbering procedure
  2. Create document using controlled template
  3. Route for review to required reviewers
  4. Address review comments and document responses
  5. Obtain required approval signatures
  6. Assign effective date and distribute
  7. Update Document Master List
  8. Validation: Document accessible at point of use; obsolete versions removed
Document Lifecycle Stages
Stage Definition Actions Required
Draft Under creation or revision Author editing, not for use
Review Circulated for review Reviewers provide feedback
Approved All signatures obtained Ready for training/distribution
Effective Training complete, released Available for use
Superseded Replaced by newer revision Remove from active use
Obsolete No longer applicable Archive per retention schedule
Document Types and Prefixes
Prefix Document Type Typical Content
QM Quality Manual QMS overview, scope, policy
SOP Standard Operating Procedure Process-level procedures
WI Work Instruction Task-level step-by-step
TF Template/Form Controlled forms
SPEC Specification Product/process specs
PLN Plan Quality/project plans
Required Reviewers by Document Type
Document Type Required Reviewers Required Approvers
SOP Process Owner, QA QA Manager, Process Owner
WI Area Supervisor, QA Area Manager
SPEC Engineering, QA Engineering Manager, QA
TF Process Owner QA
Design Documents Design Team, QA Design Control Authority

Document Numbering System

Assign consistent document numbers for identification and retrieval.

Numbering Format

Standard format: PREFIX-CATEGORY-SEQUENCE[-REVISION]

Example: SOP-02-001-A

SOP = Document type (Standard Operating Procedure)
02  = Category code (Document Control)
001 = Sequential number
A   = Revision indicator
Category Codes
Code Functional Area Description
01 Quality Management QMS procedures, management review
02 Document Control This area
03 Human Resources Training, competency
04 Design & Development Design control processes
05 Purchasing Supplier management
06 Production Manufacturing procedures
07 Quality Control Inspection, testing
08 CAPA Corrective/preventive actions
09 Risk Management ISO 14971 processes
10 Regulatory Affairs Submissions, compliance
Numbering Workflow
  1. Author requests document number from Document Control
  2. Document Control verifies category assignment
  3. Document Control assigns next available sequence number
  4. Number recorded in Document Master List
  5. Author creates document using assigned number
  6. Validation: Number format matches standard; no duplicates in Master List
Revision Designation
Change Type Revision Increment Example
Major revision Increment number Rev 01 → Rev 02
Minor revision Increment sub-revision Rev 01 → Rev 01.1
Administrative No change or letter suffix Rev 01 → Rev 01a

See references/document-control-procedures.md for complete numbering guidance.


Approval and Review Process

Obtain required reviews and approvals before document release.

Review Workflow
  1. Author completes document draft
  2. Author submits for review via routing form or DMS
  3. Reviewers assigned based on document type
  4. Reviewers provide comments within review period (5-10 business days)
  5. Author addresses comments and documents responses
  6. Author resubmits revised document
  7. Approvers sign and date
  8. Validation: All required reviewers completed; all comments addressed with documented disposition
Comment Disposition
Disposition Action Required
Accept Incorporate comment as written
Accept with modification Incorporate with changes, document rationale
Reject Do not incorporate, document justification
Defer Address in future revision, document reason
Approval Matrix
Document Level 1 (Policy/QM): CEO or delegate + QA Manager
Document Level 2 (SOP): Department Manager + QA Manager
Document Level 3 (WI/TF): Area Supervisor + QA Representative
Signature Requirements
Element Requirement
Name Printed name of signer
Signature Handwritten or electronic signature
Date Date signature applied
Role Function/role of signer

Change Control Process

Manage document changes systematically through review and approval.

Change Control Workflow
  1. Identify need for document change
  2. Complete Change Request Form with justification
  3. Document Control assigns change number and logs request
  4. Route to reviewers for impact assessment
  5. Obtain approvals based on change classification
  6. Author implements approved changes
  7. Update revision number and change history
  8. Validation: Changes match approved scope; change history complete
Change Classification
Class Definition Approval Level Examples
Administrative No content impact Document Control Typos, formatting
Minor Limited content change Process Owner + QA Clarifications
Major Significant content change Full review cycle New requirements
Emergency Urgent safety/compliance Expedited + retrospective Safety issues
Impact Assessment Checklist
Impact Area Assessment Questions
Training Does change require retraining?
Equipment Does change affect equipment or systems?
Validation Does change require revalidation?
Regulatory Does change affect regulatory filings?
Other Documents Which related documents need updating?
Records What records are affected?
Change History Documentation

Each document must include change history:

| Revision | Date | Description | Author | Approver |
|----------|------|-------------|--------|----------|
| 01 | 2023-01-15 | Initial release | J. Smith | M. Jones |
| 02 | 2024-03-01 | Updated workflow | J. Smith | M. Jones |

21 CFR Part 11 Compliance

Implement electronic record and signature controls for FDA compliance.

Part 11 Scope
Applies To Does Not Apply To
Records required by FDA regulations Paper records
Records submitted to FDA Internal non-regulated documents
Electronic signatures on required records General email communication
Electronic Record Controls
  1. Validate system for accuracy and reliability
  2. Implement secure audit trail for all changes
  3. Restrict system access to authorized individuals
  4. Generate accurate copies in human-readable format
  5. Protect records throughout retention period
  6. Validation: Audit trail captures who, what, when for all changes
Audit Trail Requirements
Requirement Implementation
Secure Cannot be modified by users
Computer-generated System creates automatically
Time-stamped Date and time of each action
Original values Previous values retained
User identity Who made each change
Electronic Signature Requirements
Requirement Implementation
Unique to individual Not shared between persons
At least 2 components User ID + password minimum
Signature manifestation Name, date/time, meaning displayed
Linked to record Cannot be excised or copied
Signature Manifestation

Every electronic signature must display:

Element Example
Printed name John Smith
Date and time 2024-03-15 14:32:05 EST
Meaning Approved for Release
System Controls Checklist

Access Controls:

  • Unique user ID for each person
  • Password complexity enforced
  • Account lockout after failed attempts
  • Session timeout after inactivity

Audit Trail:

  • All record creation logged
  • All modifications logged with old/new values
  • User identity captured
  • Date/time stamp on all entries

Security:

  • Role-based access control
  • Encryption for data at rest and in transit
  • Regular backup and tested recovery

See references/21cfr11-compliance-guide.md for detailed compliance requirements.


Reference Documentation

Document Control Procedures

references/document-control-procedures.md contains:

  • Document numbering system and format
  • Document lifecycle stages and transitions
  • Review and approval workflow details
  • Change control process with classification criteria
  • Distribution and access control methods
  • Record retention periods and disposal procedures
  • Document Master List requirements
21 CFR Part 11 Compliance Guide

references/21cfr11-compliance-guide.md contains:

  • Part 11 scope and applicability
  • Electronic record requirements (§11.10)
  • Electronic signature requirements (§11.50, 11.100, 11.200)
  • System control specifications
  • Validation approach and documentation
  • Compliance checklist and gap assessment template
  • Common FDA deficiencies and prevention

Tools

Document Validator
# Validate document metadata
python scripts/document_validator.py --doc document.json

# Interactive validation mode
python scripts/document_validator.py --interactive

# JSON output for integration
python scripts/document_validator.py --doc document.json --output json

# Generate sample document JSON
python scripts/document_validator.py --sample > sample_doc.json

Validates:

  • Document numbering convention compliance
  • Title and status requirements
  • Date validation (effective, review due)
  • Approval requirements by document type
  • Change history completeness
  • 21 CFR Part 11 controls (audit trail, signatures)
Sample Document Input
{
  "number": "SOP-02-001",
  "title": "Document Control Procedure",
  "doc_type": "SOP",
  "revision": "03",
  "status": "Effective",
  "effective_date": "2024-01-15",
  "review_date": "2025-01-15",
  "author": "J. Smith",
  "approver": "M. Jones",
  "change_history": [
    {"revision": "01", "date": "2022-01-01", "description": "Initial release"},
    {"revision": "02", "date": "2023-01-15", "description": "Updated workflow"},
    {"revision": "03", "date": "2024-01-15", "description": "Added e-signature requirements"}
  ],
  "has_audit_trail": true,
  "has_electronic_signature": true,
  "signature_components": 2
}

Document Control Metrics

Track document control system performance.

Key Performance Indicators
Metric Target Calculation
Document cycle time <30 days Average days from draft to effective
Review completion rate >95% Reviews completed on time / Total reviews
Change request backlog <10 Open change requests at month end
Overdue review rate <5% Documents past review date / Total effective
Audit finding rate <2 per audit Document control findings per internal audit
Periodic Review Schedule
Document Type Review Frequency
Policy Every 3 years
SOP Every 2 years
WI Every 2 years
Specifications As needed or with product changes
Forms/Templates Every 3 years

Regulatory Requirements

ISO 13485:2016 Clause 4.2
Sub-clause Requirement
4.2.1 Quality management system documentation
4.2.2 Quality manual
4.2.3 Medical device file (technical documentation)
4.2.4 Control of documents
4.2.5 Control of records
FDA document & record control — ISO 13485 §4.2 under the QMSR (legacy QSR sections, historical)

⚠️ STATUS — QMSR transition (effective 2026-02-02): FDA's Quality Management System Regulation (QMSR) final rule (89 FR 7496) amended 21 CFR Part 820 to incorporate ISO 13485:2016 by reference and removed the legacy QSR subsection structure. The section numbers in the table below (820.40/.180/.181/.184/.186) no longer exist in the CFR; they are retained only as a familiar index. Current document/record control authority is ISO 13485:2016 §4.2 (esp. §4.2.4 control of documents, §4.2.5 control of records), with the medical device file in §4.2.3 and records additions in retained 21 CFR 820.35. Cite the ISO 13485 clauses — not the 820.x numbers — in current compliance documentation.

Legacy QSR Section (historical, pre-2026) Requirement Current authority under QMSR (legacy QSR shown for index)
820.40 Document controls ISO 13485 §4.2.4
820.180 General record requirements ISO 13485 §4.2.5 + 21 CFR 820.35 (retained)
820.181 Device master record ISO 13485 §4.2.3 (medical device file)
820.184 Device history record ISO 13485 §4.2.5 + 21 CFR 820.35 (retained)
820.186 Quality system record ISO 13485 §4.2.5 + 21 CFR 820.35 (retained)
Common Audit Findings
Finding Prevention
Obsolete documents in use Implement distribution control
Missing approval signatures Enforce workflow before release
Incomplete change history Require history update with each revision
No periodic review schedule Establish and enforce review calendar
Inadequate audit trail Validate DMS for Part 11 compliance

Decision discipline: The validator scripts in this skill check structure and completeness — they do not certify a document or record as compliant. Approval and release decisions are yours and the document owner's to make under your controlled procedure; route regulatory-classification or submission-record questions to Regulatory Affairs.

1---
2name: "quality-documentation-manager"
3description: Document control system management for medical device QMS. Covers document numbering, version control, change management, and 21 CFR Part 11 compliance. Use when working on document control procedures, change control workflows, document numbering, version management, electronic signature compliance, or regulatory documentation review.
4triggers:
5 - document control
6 - document numbering
7 - version control
8 - change control
9 - document approval
10 - electronic signature
11 - 21 CFR Part 11
12 - audit trail
13 - document lifecycle
14 - controlled document
15 - document master list
16 - record retention
17---
18 
19# Quality Documentation Manager
20 
21Document control system design and management for ISO 13485-compliant quality management systems, including numbering conventions, approval workflows, change control, and electronic record compliance.
22 
23---
24 
25## Table of Contents
26 
27- [Document Control Workflow](#document-control-workflow)
28- [Document Numbering System](#document-numbering-system)
29- [Approval and Review Process](#approval-and-review-process)
30- [Change Control Process](#change-control-process)
31- [21 CFR Part 11 Compliance](#21-cfr-part-11-compliance)
32- [Reference Documentation](#reference-documentation)
33- [Tools](#tools)
34 
35---
36 
37## Document Control Workflow
38 
39Implement document control from creation through obsolescence:
40 
411. Assign document number per numbering procedure
422. Create document using controlled template
433. Route for review to required reviewers
444. Address review comments and document responses
455. Obtain required approval signatures
466. Assign effective date and distribute
477. Update Document Master List
488. **Validation:** Document accessible at point of use; obsolete versions removed
49 
50### Document Lifecycle Stages
51 
52| Stage | Definition | Actions Required |
53|-------|------------|------------------|
54| Draft | Under creation or revision | Author editing, not for use |
55| Review | Circulated for review | Reviewers provide feedback |
56| Approved | All signatures obtained | Ready for training/distribution |
57| Effective | Training complete, released | Available for use |
58| Superseded | Replaced by newer revision | Remove from active use |
59| Obsolete | No longer applicable | Archive per retention schedule |
60 
61### Document Types and Prefixes
62 
63| Prefix | Document Type | Typical Content |
64|--------|---------------|-----------------|
65| QM | Quality Manual | QMS overview, scope, policy |
66| SOP | Standard Operating Procedure | Process-level procedures |
67| WI | Work Instruction | Task-level step-by-step |
68| TF | Template/Form | Controlled forms |
69| SPEC | Specification | Product/process specs |
70| PLN | Plan | Quality/project plans |
71 
72### Required Reviewers by Document Type
73 
74| Document Type | Required Reviewers | Required Approvers |
75|---------------|-------------------|-------------------|
76| SOP | Process Owner, QA | QA Manager, Process Owner |
77| WI | Area Supervisor, QA | Area Manager |
78| SPEC | Engineering, QA | Engineering Manager, QA |
79| TF | Process Owner | QA |
80| Design Documents | Design Team, QA | Design Control Authority |
81 
82---
83 
84## Document Numbering System
85 
86Assign consistent document numbers for identification and retrieval.
87 
88### Numbering Format
89 
90Standard format: `PREFIX-CATEGORY-SEQUENCE[-REVISION]`
91 
92```
93Example: SOP-02-001-A
94 
95SOP = Document type (Standard Operating Procedure)
9602 = Category code (Document Control)
97001 = Sequential number
98A = Revision indicator
99```
100 
101### Category Codes
102 
103| Code | Functional Area | Description |
104|------|-----------------|-------------|
105| 01 | Quality Management | QMS procedures, management review |
106| 02 | Document Control | This area |
107| 03 | Human Resources | Training, competency |
108| 04 | Design & Development | Design control processes |
109| 05 | Purchasing | Supplier management |
110| 06 | Production | Manufacturing procedures |
111| 07 | Quality Control | Inspection, testing |
112| 08 | CAPA | Corrective/preventive actions |
113| 09 | Risk Management | ISO 14971 processes |
114| 10 | Regulatory Affairs | Submissions, compliance |
115 
116### Numbering Workflow
117 
1181. Author requests document number from Document Control
1192. Document Control verifies category assignment
1203. Document Control assigns next available sequence number
1214. Number recorded in Document Master List
1225. Author creates document using assigned number
1236. **Validation:** Number format matches standard; no duplicates in Master List
124 
125### Revision Designation
126 
127| Change Type | Revision Increment | Example |
128|-------------|-------------------|---------|
129| Major revision | Increment number | Rev 01 → Rev 02 |
130| Minor revision | Increment sub-revision | Rev 01 → Rev 01.1 |
131| Administrative | No change or letter suffix | Rev 01 → Rev 01a |
132 
133See `references/document-control-procedures.md` for complete numbering guidance.
134 
135---
136 
137## Approval and Review Process
138 
139Obtain required reviews and approvals before document release.
140 
141### Review Workflow
142 
1431. Author completes document draft
1442. Author submits for review via routing form or DMS
1453. Reviewers assigned based on document type
1464. Reviewers provide comments within review period (5-10 business days)
1475. Author addresses comments and documents responses
1486. Author resubmits revised document
1497. Approvers sign and date
1508. **Validation:** All required reviewers completed; all comments addressed with documented disposition
151 
152### Comment Disposition
153 
154| Disposition | Action Required |
155|-------------|-----------------|
156| Accept | Incorporate comment as written |
157| Accept with modification | Incorporate with changes, document rationale |
158| Reject | Do not incorporate, document justification |
159| Defer | Address in future revision, document reason |
160 
161### Approval Matrix
162 
163```
164Document Level 1 (Policy/QM): CEO or delegate + QA Manager
165Document Level 2 (SOP): Department Manager + QA Manager
166Document Level 3 (WI/TF): Area Supervisor + QA Representative
167```
168 
169### Signature Requirements
170 
171| Element | Requirement |
172|---------|-------------|
173| Name | Printed name of signer |
174| Signature | Handwritten or electronic signature |
175| Date | Date signature applied |
176| Role | Function/role of signer |
177 
178---
179 
180## Change Control Process
181 
182Manage document changes systematically through review and approval.
183 
184### Change Control Workflow
185 
1861. Identify need for document change
1872. Complete Change Request Form with justification
1883. Document Control assigns change number and logs request
1894. Route to reviewers for impact assessment
1905. Obtain approvals based on change classification
1916. Author implements approved changes
1927. Update revision number and change history
1938. **Validation:** Changes match approved scope; change history complete
194 
195### Change Classification
196 
197| Class | Definition | Approval Level | Examples |
198|-------|------------|----------------|----------|
199| Administrative | No content impact | Document Control | Typos, formatting |
200| Minor | Limited content change | Process Owner + QA | Clarifications |
201| Major | Significant content change | Full review cycle | New requirements |
202| Emergency | Urgent safety/compliance | Expedited + retrospective | Safety issues |
203 
204### Impact Assessment Checklist
205 
206| Impact Area | Assessment Questions |
207|-------------|---------------------|
208| Training | Does change require retraining? |
209| Equipment | Does change affect equipment or systems? |
210| Validation | Does change require revalidation? |
211| Regulatory | Does change affect regulatory filings? |
212| Other Documents | Which related documents need updating? |
213| Records | What records are affected? |
214 
215### Change History Documentation
216 
217Each document must include change history:
218 
219```
220| Revision | Date | Description | Author | Approver |
221|----------|------|-------------|--------|----------|
222| 01 | 2023-01-15 | Initial release | J. Smith | M. Jones |
223| 02 | 2024-03-01 | Updated workflow | J. Smith | M. Jones |
224```
225 
226---
227 
228## 21 CFR Part 11 Compliance
229 
230Implement electronic record and signature controls for FDA compliance.
231 
232### Part 11 Scope
233 
234| Applies To | Does Not Apply To |
235|------------|-------------------|
236| Records required by FDA regulations | Paper records |
237| Records submitted to FDA | Internal non-regulated documents |
238| Electronic signatures on required records | General email communication |
239 
240### Electronic Record Controls
241 
2421. Validate system for accuracy and reliability
2432. Implement secure audit trail for all changes
2443. Restrict system access to authorized individuals
2454. Generate accurate copies in human-readable format
2465. Protect records throughout retention period
2476. **Validation:** Audit trail captures who, what, when for all changes
248 
249### Audit Trail Requirements
250 
251| Requirement | Implementation |
252|-------------|----------------|
253| Secure | Cannot be modified by users |
254| Computer-generated | System creates automatically |
255| Time-stamped | Date and time of each action |
256| Original values | Previous values retained |
257| User identity | Who made each change |
258 
259### Electronic Signature Requirements
260 
261| Requirement | Implementation |
262|-------------|----------------|
263| Unique to individual | Not shared between persons |
264| At least 2 components | User ID + password minimum |
265| Signature manifestation | Name, date/time, meaning displayed |
266| Linked to record | Cannot be excised or copied |
267 
268### Signature Manifestation
269 
270Every electronic signature must display:
271 
272| Element | Example |
273|---------|---------|
274| Printed name | John Smith |
275| Date and time | 2024-03-15 14:32:05 EST |
276| Meaning | Approved for Release |
277 
278### System Controls Checklist
279 
280**Access Controls:**
281- [ ] Unique user ID for each person
282- [ ] Password complexity enforced
283- [ ] Account lockout after failed attempts
284- [ ] Session timeout after inactivity
285 
286**Audit Trail:**
287- [ ] All record creation logged
288- [ ] All modifications logged with old/new values
289- [ ] User identity captured
290- [ ] Date/time stamp on all entries
291 
292**Security:**
293- [ ] Role-based access control
294- [ ] Encryption for data at rest and in transit
295- [ ] Regular backup and tested recovery
296 
297See `references/21cfr11-compliance-guide.md` for detailed compliance requirements.
298 
299---
300 
301## Reference Documentation
302 
303### Document Control Procedures
304 
305`references/document-control-procedures.md` contains:
306 
307- Document numbering system and format
308- Document lifecycle stages and transitions
309- Review and approval workflow details
310- Change control process with classification criteria
311- Distribution and access control methods
312- Record retention periods and disposal procedures
313- Document Master List requirements
314 
315### 21 CFR Part 11 Compliance Guide
316 
317`references/21cfr11-compliance-guide.md` contains:
318 
319- Part 11 scope and applicability
320- Electronic record requirements (§11.10)
321- Electronic signature requirements (§11.50, 11.100, 11.200)
322- System control specifications
323- Validation approach and documentation
324- Compliance checklist and gap assessment template
325- Common FDA deficiencies and prevention
326 
327---
328 
329## Tools
330 
331### Document Validator
332 
333```bash
334# Validate document metadata
335python scripts/document_validator.py --doc document.json
336 
337# Interactive validation mode
338python scripts/document_validator.py --interactive
339 
340# JSON output for integration
341python scripts/document_validator.py --doc document.json --output json
342 
343# Generate sample document JSON
344python scripts/document_validator.py --sample > sample_doc.json
345```
346 
347Validates:
348- Document numbering convention compliance
349- Title and status requirements
350- Date validation (effective, review due)
351- Approval requirements by document type
352- Change history completeness
353- 21 CFR Part 11 controls (audit trail, signatures)
354 
355### Sample Document Input
356 
357```json
358{
359 "number": "SOP-02-001",
360 "title": "Document Control Procedure",
361 "doc_type": "SOP",
362 "revision": "03",
363 "status": "Effective",
364 "effective_date": "2024-01-15",
365 "review_date": "2025-01-15",
366 "author": "J. Smith",
367 "approver": "M. Jones",
368 "change_history": [
369 {"revision": "01", "date": "2022-01-01", "description": "Initial release"},
370 {"revision": "02", "date": "2023-01-15", "description": "Updated workflow"},
371 {"revision": "03", "date": "2024-01-15", "description": "Added e-signature requirements"}
372 ],
373 "has_audit_trail": true,
374 "has_electronic_signature": true,
375 "signature_components": 2
376}
377```
378 
379---
380 
381## Document Control Metrics
382 
383Track document control system performance.
384 
385### Key Performance Indicators
386 
387| Metric | Target | Calculation |
388|--------|--------|-------------|
389| Document cycle time | <30 days | Average days from draft to effective |
390| Review completion rate | >95% | Reviews completed on time / Total reviews |
391| Change request backlog | <10 | Open change requests at month end |
392| Overdue review rate | <5% | Documents past review date / Total effective |
393| Audit finding rate | <2 per audit | Document control findings per internal audit |
394 
395### Periodic Review Schedule
396 
397| Document Type | Review Frequency |
398|---------------|------------------|
399| Policy | Every 3 years |
400| SOP | Every 2 years |
401| WI | Every 2 years |
402| Specifications | As needed or with product changes |
403| Forms/Templates | Every 3 years |
404 
405---
406 
407## Regulatory Requirements
408 
409### ISO 13485:2016 Clause 4.2
410 
411| Sub-clause | Requirement |
412|------------|-------------|
413| 4.2.1 | Quality management system documentation |
414| 4.2.2 | Quality manual |
415| 4.2.3 | Medical device file (technical documentation) |
416| 4.2.4 | Control of documents |
417| 4.2.5 | Control of records |
418 
419### FDA document & record control — ISO 13485 §4.2 under the QMSR (legacy QSR sections, historical)
420 
421> **⚠️ STATUS — QMSR transition (effective 2026-02-02):** FDA's Quality Management System Regulation (QMSR) final rule (89 FR 7496) amended 21 CFR Part 820 to **incorporate ISO 13485:2016 by reference** and removed the legacy QSR subsection structure. The section numbers in the table below (820.40/.180/.181/.184/.186) **no longer exist in the CFR**; they are retained only as a familiar index. Current document/record control authority is **ISO 13485:2016 §4.2** (esp. §4.2.4 control of documents, §4.2.5 control of records), with the medical device file in §4.2.3 and records additions in retained **21 CFR 820.35**. Cite the ISO 13485 clauses — not the 820.x numbers — in current compliance documentation.
422 
423| Legacy QSR Section (historical, pre-2026) | Requirement | Current authority under QMSR (legacy QSR shown for index) |
424|-------------------------------------------|-------------|------------------------------|
425| 820.40 | Document controls | ISO 13485 §4.2.4 |
426| 820.180 | General record requirements | ISO 13485 §4.2.5 + 21 CFR 820.35 (retained) |
427| 820.181 | Device master record | ISO 13485 §4.2.3 (medical device file) |
428| 820.184 | Device history record | ISO 13485 §4.2.5 + 21 CFR 820.35 (retained) |
429| 820.186 | Quality system record | ISO 13485 §4.2.5 + 21 CFR 820.35 (retained) |
430 
431### Common Audit Findings
432 
433| Finding | Prevention |
434|---------|------------|
435| Obsolete documents in use | Implement distribution control |
436| Missing approval signatures | Enforce workflow before release |
437| Incomplete change history | Require history update with each revision |
438| No periodic review schedule | Establish and enforce review calendar |
439| Inadequate audit trail | Validate DMS for Part 11 compliance |
440 
441> **Decision discipline:** The validator scripts in this skill check structure and completeness — they do not certify a document or record as compliant. Approval and release decisions are yours and the document owner's to make under your controlled procedure; route regulatory-classification or submission-record questions to Regulatory Affairs.
442 

Discussion

Alternatives

Also in Developer docsSee all 533 in Development →