Quality Manager - QMS ISO 13485 Specialist

ISO 13485 Quality Management System implementation and maintenance for medical device organizations.

How to use it

Claude Code
  1. Run the line below. It pulls the whole folder into ~/.claude/skills/quality-manager-qms-iso13485, including the files SKILL.md points to.
  2. Describe your job in plain words. Claude Code follows the skill from there.
Claude Code — installs the whole folder, not just SKILL.md
npx degit alirezarezvani/claude-skills/ra-qm-team/skills/quality-manager-qms-iso13485#main ~/.claude/skills/quality-manager-qms-iso13485

For one project only, change the path to .claude/skills/quality-manager-qms-iso13485. This skill also uses qms-process-templates.md, iso13485-clause-requirements.md, qms_audit_checklist.py — copying SKILL.md alone won't be enough. See the folder on GitHub.

Claude (web or desktop app)
  1. On this page open ⋯ → Download .md.
  2. Save it as SKILL.md in a folder, zip the folder, then Customize → Skills → + → Create skill → Upload a skill.
  3. Pick the file and Save. Claude shows the name and description and runs a security scan.
  4. Check the skill is switched on.
  5. Start a new chat and describe your job in plain words. The AI follows the skill from there.
ChatGPT or another app
  1. ChatGPT: make a Project and paste it into Instructions.
  2. Neither? Paste it at the top of a new chat — it works for that chat.
Not working?
  • Check which app you pasted it into — the steps above name the right one.
  • Some skills need the paid tier of Claude or ChatGPT.
Step-by-step guide with screenshots · Ask in the forum

Paste into Claude, ChatGPT or Cursor.

Source of Quality Manager - QMS ISO 13485 Specialist

Show the full text440 lines
namedescriptiontriggers
quality-manager-qms-iso13485ISO 13485 Quality Management System implementation and maintenance for medical device organizations. Provides QMS design, documentation control, internal auditing, CAPA management, and certification support. Use when working with medical device quality systems, preparing for ISO 13485 audits, managing regulatory compliance documentation, setting up corrective actions, or building audit preparation programs. Useful for quality management, audit preparation, regulatory compliance, medical device documentation, and corrective action workflows. - ISO 13485 - QMS implementation - quality management system - document control - internal audit - management review - quality manual - CAPA process - process validation - design control - supplier qualification - quality records

Quality Manager - QMS ISO 13485 Specialist

ISO 13485:2016 Quality Management System implementation, maintenance, and certification support for medical device organizations.


Table of Contents


QMS Implementation Workflow

Implement ISO 13485:2016 compliant quality management system from gap analysis through certification.

Workflow: Initial QMS Implementation
  1. Conduct gap analysis against ISO 13485:2016 requirements
  2. Document current state vs. required state for each clause
  3. Prioritize gaps by:
    • Regulatory criticality
    • Risk to product safety
    • Resource requirements
  4. Develop implementation roadmap with milestones
  5. Establish Quality Manual per Clause 4.2.2:
    • QMS scope with justified exclusions
    • Process interactions
    • Procedure references
  6. Create required documented procedures — see Mandatory Documented Procedures for the full list
  7. Deploy processes with training
  8. Validation: Gap analysis complete; Quality Manual approved; all required procedures documented and trained

Use the Gap Analysis Matrix template in qms-process-templates.md to document clause-by-clause current state, gaps, priority, and actions.

QMS Structure
Level Document Type Example
1 Quality Manual QM-001
2 Procedures SOP-02-001
3 Work Instructions WI-06-012
4 Records Training records

Document Control Workflow

Establish and maintain document control per ISO 13485 Clause 4.2.3.

Workflow: Document Creation and Approval
  1. Identify need for new document or revision
  2. Assign document number per numbering convention:
    • Format: [TYPE]-[AREA]-[SEQUENCE]-[REV]
    • Example: SOP-02-001-01
  3. Draft document using approved template
  4. Route for review to subject matter experts
  5. Collect and address review comments
  6. Obtain required approvals based on document type
  7. Update Document Master List
  8. Validation: Document numbered correctly; all reviewers signed; Master List updated
Document Numbering Convention
Prefix Document Type Approval Authority
QM Quality Manual Management Rep + CEO
POL Policy Department Head + QA
SOP Procedure Process Owner + QA
WI Work Instruction Supervisor + QA
TF Template/Form Process Owner
SPEC Specification Engineering + QA
Area Codes
Code Area Examples
01 Quality Management Quality Manual, policy
02 Document Control This procedure
03 Training Competency procedures
04 Design Design control
05 Purchasing Supplier management
06 Production Manufacturing
07 Quality Control Inspection, testing
08 CAPA Corrective actions
Document Change Control
Change Type Approval Level Examples
Administrative Document Control Typos, formatting
Minor Process Owner + QA Clarifications
Major Full review cycle Process changes
Emergency Expedited + retrospective Safety issues
Document Review Schedule
Document Type Review Period Trigger for Unscheduled Review
Quality Manual Annual Organizational change
Procedures Annual Audit finding, regulation change
Work Instructions 2 years Process change
Forms 2 years User feedback

Internal Audit Workflow

Plan and execute internal audits per ISO 13485 Clause 8.2.4.

Workflow: Annual Audit Program
  1. Identify processes and areas requiring audit coverage
  2. Assess risk factors for audit frequency:
    • Previous audit findings
    • Regulatory changes
    • Process changes
    • Complaint trends
  3. Assign qualified auditors (independent of area audited)
  4. Develop annual audit schedule
  5. Obtain management approval
  6. Communicate schedule to process owners
  7. Track completion and reschedule as needed
  8. Validation: All processes covered; auditors qualified and independent; schedule approved

Use the Audit Program Template in qms-process-templates.md to schedule audits by clause and quarter across processes such as Document Control (4.2.3/4.2.4), Management Review (5.6), Design Control (7.3), Production (7.5), and CAPA (8.5.2/8.5.3).

Workflow: Individual Audit Execution
  1. Prepare audit plan with scope, criteria, and schedule
  2. Notify auditee minimum 1 week prior
  3. Review procedures and previous audit results
  4. Prepare audit checklist
  5. Conduct opening meeting
  6. Collect evidence through:
    • Document review
    • Record sampling
    • Process observation
    • Personnel interviews
  7. Classify findings:
    • Major NC: Absence or breakdown of system
    • Minor NC: Single lapse or deviation
    • Observation: Risk of future NC
  8. Conduct closing meeting
  9. Issue audit report within 5 business days
  10. Validation: All checklist items addressed; findings supported by evidence; report distributed
Auditor Qualification Requirements
Criterion Requirement
Training ISO 13485 awareness + auditor training
Experience Minimum 1 audit as observer
Independence Not auditing own work area
Competence Understanding of audited process
Finding Classification Guide
Classification Criteria Response Time
Major NC System absence, total breakdown, regulatory violation 30 days for CAPA
Minor NC Single instance, partial compliance 60 days for CAPA
Observation Potential risk, improvement opportunity Track in next audit

Process Validation Workflow

Validate special processes per ISO 13485 Clause 7.5.6.

Workflow: Process Validation Protocol
  1. Identify processes requiring validation:
    • Output cannot be verified by inspection
    • Deficiencies appear only in use
    • Sterilization, welding, sealing, software
  2. Form validation team with subject matter experts
  3. Write validation protocol including:
    • Process description and parameters
    • Equipment and materials
    • Acceptance criteria
    • Statistical approach
  4. Execute IQ: verify equipment installed correctly and document specifications
  5. Execute OQ: test parameter ranges and verify process control
  6. Execute PQ: run production conditions and verify output meets requirements
  7. Write validation report with conclusions
  8. Validation: IQ/OQ/PQ complete; acceptance criteria met; validation report approved
Validation Documentation Requirements
Phase Content Evidence
Protocol Objectives, methods, criteria Approved protocol
IQ Equipment verification Installation records
OQ Parameter verification Test results
PQ Performance verification Production data
Report Summary, conclusions Approval signatures
Revalidation Triggers
Trigger Action Required
Equipment change Assess impact, revalidate affected phases
Parameter change OQ and PQ minimum
Material change Assess impact, PQ minimum
Process failure Full revalidation
Periodic Per validation schedule (typically 3 years)
Special Process Examples
Process Validation Standard Critical Parameters
EO Sterilization ISO 11135 Temperature, humidity, EO concentration, time
Steam Sterilization ISO 17665 Temperature, pressure, time
Radiation Sterilization ISO 11137 Dose, dose uniformity
Sealing Internal Temperature, pressure, dwell time
Welding ISO 11607 Heat, pressure, speed

Supplier Qualification Workflow

Evaluate and approve suppliers per ISO 13485 Clause 7.4.

Workflow: New Supplier Qualification
  1. Identify supplier category:
    • Category A: Critical (affects safety/performance)
    • Category B: Major (affects quality)
    • Category C: Minor (indirect impact)
  2. Request supplier information:
    • Quality certifications
    • Product specifications
    • Quality history
  3. Evaluate supplier based on:
    • Quality system (ISO certification)
    • Technical capability
    • Quality history
    • Financial stability
  4. For Category A suppliers:
    • Conduct on-site audit
    • Require quality agreement
  5. Calculate qualification score
  6. Make approval decision:
    • 80: Approved

    • 60-80: Conditional approval
    • <60: Not approved
  7. Add to Approved Supplier List
  8. Validation: Evaluation criteria scored; qualification records complete; supplier categorized
Supplier Evaluation Criteria
Criterion Weight Scoring
Quality System 30% ISO 13485=30, ISO 9001=20, Documented=10, None=0
Quality History 25% Reject rate: <1%=25, 1-3%=15, >3%=0
Delivery 20% On-time: >95%=20, 90-95%=10, <90%=0
Technical Capability 15% Exceeds=15, Meets=10, Marginal=5
Financial Stability 10% Strong=10, Adequate=5, Questionable=0
Supplier Category Requirements
Category Qualification Monitoring Agreement
A - Critical On-site audit Annual review Quality agreement
B - Major Questionnaire Semi-annual review Quality requirements
C - Minor Assessment Issue-based Standard terms
Supplier Performance Metrics
Metric Target Calculation
Accept Rate >98% (Accepted lots / Total lots) × 100
On-Time Delivery >95% (On-time / Total orders) × 100
Response Time <5 days Average days to resolve issues
Documentation 100% (Complete CoCs / Required CoCs) × 100

QMS Process Reference

For detailed requirements and audit questions for each ISO 13485:2016 clause, see iso13485-clause-requirements.md.

Management Review Required Inputs (Clause 5.6.2)
Input Source Prepared By
Audit results Internal and external audits QA Manager
Customer feedback Complaints, surveys Customer Quality
Process performance Process metrics Process Owners
Product conformity Inspection data, NCs QC Manager
CAPA status CAPA system CAPA Officer
Previous actions Prior review records QMR
Changes affecting QMS Regulatory, organizational RA Manager
Recommendations All sources All Managers
Record Retention Requirements

⚠️ STATUS — QMSR transition (effective 2026-02-02): FDA's Quality Management System Regulation (QMSR) final rule (89 FR 7496) amended 21 CFR Part 820 to incorporate ISO 13485:2016 by reference and removed the legacy QSR subsection structure. The section numbers below (820.30/.181/.184/.198) no longer exist in the CFR — they are retained only as a familiar index. The current authority for record retention is ISO 13485:2016 §4.2.5 (retain "for at least the lifetime of the medical device as defined by the organization, but not less than two years"), with records additions in retained 21 CFR 820.35. Cite the ISO 13485 clauses — not the 820.x numbers — in current compliance documentation.

Record Type Minimum Retention Current authority under QMSR (legacy QSR shown for index)
Device Master Record Life of device + 2 years ISO 13485 §4.2.3 (medical device file)/§4.2.5 (legacy QSR 820.181, historical)
Device History Record Life of device + 2 years ISO 13485 §4.2.5 + 21 CFR 820.35 (legacy QSR 820.184, historical)
Design History File Life of device + 2 years ISO 13485 §7.3.10/§4.2.5 (legacy QSR 820.30, historical)
Complaint Records Life of device + 2 years ISO 13485 §8.2.2/§4.2.5 + 21 CFR 820.35(b) (legacy QSR 820.198, historical)
Training Records Employment + 3 years Best practice
Audit Records 7 years Best practice
CAPA Records 7 years Best practice
Calibration Records Equipment life + 2 years Best practice

Decision discipline: This skill's checklists and tools structure QMS conformity assessment — they do not certify ISO 13485 / QMSR compliance. Final compliance determinations and record-retention decisions are yours to make and must be reviewed and signed off by the named QMR; route FDA-specific regulatory-classification questions to Regulatory Affairs and confirm current 21 CFR 820 / ISO 13485:2016 text at fda.gov before relying on any citation here.


Decision Frameworks

Exclusion Justification (Clause 4.2.2)
Clause Permissible Exclusion Justification Required
6.4.2 Contamination control Product not affected by contamination
7.3 Design and development Organization does not design products
7.5.2 Product cleanliness No cleanliness requirements
7.5.3 Installation No installation activities
7.5.4 Servicing No servicing activities
7.5.5 Sterile products No sterile products
Nonconformity Disposition Decision Tree
Nonconforming Product Identified
            │
            ▼
    Can it be reworked?
            │
       Yes──┴──No
        │       │
        ▼       ▼
    Is rework     Can it be used
    procedure     as is?
    available?        │
        │        Yes──┴──No
    Yes─┴─No     │       │
     │    │     ▼       ▼
     ▼    ▼  Concession  Scrap or
  Rework  Create    approval    return to
  per SOP  rework    needed?    supplier
          procedure     │
                    Yes─┴─No
                     │    │
                     ▼    ▼
                 Customer  Use as is
                 approval  with MRB
                          approval
CAPA Initiation Criteria
Source Automatic CAPA Evaluate for CAPA
Customer complaint Safety-related All others
External audit Major NC Minor NC
Internal audit Major NC Repeat minor NC
Product NC Field failure Trend exceeds threshold
Process deviation Safety impact Repeated deviations

Tools and References

Scripts
Tool Purpose Usage
qms_audit_checklist.py Generate audit checklists by clause or process python qms_audit_checklist.py --help

Audit Checklist Generator Features:

  • Generate clause-specific checklists (e.g., --clause 7.3)
  • Generate process-based checklists (e.g., --process design-control)
  • Full system audit checklist (--audit-type system)
  • Text or JSON output formats
  • Interactive mode for guided selection
References
Document Content
iso13485-clause-requirements.md Detailed requirements for each ISO 13485:2016 clause with audit questions
qms-process-templates.md Ready-to-use templates for gap analysis, audit program, document control, CAPA, supplier, training
Quick Reference: Mandatory Documented Procedures
Procedure Clause Key Elements
Document Control 4.2.3 Approval, distribution, obsolete control
Record Control 4.2.4 Identification, retention, disposal
Internal Audit 8.2.4 Program, auditor qualification, reporting
NC Product Control 8.3 Identification, segregation, disposition
Corrective Action 8.5.2 Root cause, implementation, verification
Preventive Action 8.5.3 Risk identification, implementation

Skill Integration Point
quality-manager-qmr Management review, quality policy
capa-officer CAPA system management
qms-audit-expert Advanced audit techniques
quality-documentation-manager DHF, DMR, DHR management
risk-management-specialist ISO 14971 integration
1---
2name: "quality-manager-qms-iso13485"
3description: ISO 13485 Quality Management System implementation and maintenance for medical device organizations. Provides QMS design, documentation control, internal auditing, CAPA management, and certification support. Use when working with medical device quality systems, preparing for ISO 13485 audits, managing regulatory compliance documentation, setting up corrective actions, or building audit preparation programs. Useful for quality management, audit preparation, regulatory compliance, medical device documentation, and corrective action workflows.
4triggers:
5 - ISO 13485
6 - QMS implementation
7 - quality management system
8 - document control
9 - internal audit
10 - management review
11 - quality manual
12 - CAPA process
13 - process validation
14 - design control
15 - supplier qualification
16 - quality records
17---
18 
19# Quality Manager - QMS ISO 13485 Specialist
20 
21ISO 13485:2016 Quality Management System implementation, maintenance, and certification support for medical device organizations.
22 
23---
24 
25## Table of Contents
26 
27- [QMS Implementation Workflow](#qms-implementation-workflow)
28- [Document Control Workflow](#document-control-workflow)
29- [Internal Audit Workflow](#internal-audit-workflow)
30- [Process Validation Workflow](#process-validation-workflow)
31- [Supplier Qualification Workflow](#supplier-qualification-workflow)
32- [QMS Process Reference](#qms-process-reference)
33- [Decision Frameworks](#decision-frameworks)
34- [Tools and References](#tools-and-references)
35 
36---
37 
38## QMS Implementation Workflow
39 
40Implement ISO 13485:2016 compliant quality management system from gap analysis through certification.
41 
42### Workflow: Initial QMS Implementation
43 
441. Conduct gap analysis against ISO 13485:2016 requirements
452. Document current state vs. required state for each clause
463. Prioritize gaps by:
47 - Regulatory criticality
48 - Risk to product safety
49 - Resource requirements
504. Develop implementation roadmap with milestones
515. Establish Quality Manual per Clause 4.2.2:
52 - QMS scope with justified exclusions
53 - Process interactions
54 - Procedure references
556. Create required documented procedures — see [Mandatory Documented Procedures](#quick-reference-mandatory-documented-procedures) for the full list
567. Deploy processes with training
578. **Validation:** Gap analysis complete; Quality Manual approved; all required procedures documented and trained
58 
59> Use the Gap Analysis Matrix template in [qms-process-templates.md](references/qms-process-templates.md) to document clause-by-clause current state, gaps, priority, and actions.
60 
61### QMS Structure
62 
63| Level | Document Type | Example |
64|-------|---------------|---------|
65| 1 | Quality Manual | QM-001 |
66| 2 | Procedures | SOP-02-001 |
67| 3 | Work Instructions | WI-06-012 |
68| 4 | Records | Training records |
69 
70---
71 
72## Document Control Workflow
73 
74Establish and maintain document control per ISO 13485 Clause 4.2.3.
75 
76### Workflow: Document Creation and Approval
77 
781. Identify need for new document or revision
792. Assign document number per numbering convention:
80 - Format: `[TYPE]-[AREA]-[SEQUENCE]-[REV]`
81 - Example: `SOP-02-001-01`
823. Draft document using approved template
834. Route for review to subject matter experts
845. Collect and address review comments
856. Obtain required approvals based on document type
867. Update Document Master List
878. **Validation:** Document numbered correctly; all reviewers signed; Master List updated
88 
89### Document Numbering Convention
90 
91| Prefix | Document Type | Approval Authority |
92|--------|---------------|-------------------|
93| QM | Quality Manual | Management Rep + CEO |
94| POL | Policy | Department Head + QA |
95| SOP | Procedure | Process Owner + QA |
96| WI | Work Instruction | Supervisor + QA |
97| TF | Template/Form | Process Owner |
98| SPEC | Specification | Engineering + QA |
99 
100### Area Codes
101 
102| Code | Area | Examples |
103|------|------|----------|
104| 01 | Quality Management | Quality Manual, policy |
105| 02 | Document Control | This procedure |
106| 03 | Training | Competency procedures |
107| 04 | Design | Design control |
108| 05 | Purchasing | Supplier management |
109| 06 | Production | Manufacturing |
110| 07 | Quality Control | Inspection, testing |
111| 08 | CAPA | Corrective actions |
112 
113### Document Change Control
114 
115| Change Type | Approval Level | Examples |
116|-------------|----------------|----------|
117| Administrative | Document Control | Typos, formatting |
118| Minor | Process Owner + QA | Clarifications |
119| Major | Full review cycle | Process changes |
120| Emergency | Expedited + retrospective | Safety issues |
121 
122### Document Review Schedule
123 
124| Document Type | Review Period | Trigger for Unscheduled Review |
125|---------------|---------------|-------------------------------|
126| Quality Manual | Annual | Organizational change |
127| Procedures | Annual | Audit finding, regulation change |
128| Work Instructions | 2 years | Process change |
129| Forms | 2 years | User feedback |
130 
131---
132 
133## Internal Audit Workflow
134 
135Plan and execute internal audits per ISO 13485 Clause 8.2.4.
136 
137### Workflow: Annual Audit Program
138 
1391. Identify processes and areas requiring audit coverage
1402. Assess risk factors for audit frequency:
141 - Previous audit findings
142 - Regulatory changes
143 - Process changes
144 - Complaint trends
1453. Assign qualified auditors (independent of area audited)
1464. Develop annual audit schedule
1475. Obtain management approval
1486. Communicate schedule to process owners
1497. Track completion and reschedule as needed
1508. **Validation:** All processes covered; auditors qualified and independent; schedule approved
151 
152> Use the Audit Program Template in [qms-process-templates.md](references/qms-process-templates.md) to schedule audits by clause and quarter across processes such as Document Control (4.2.3/4.2.4), Management Review (5.6), Design Control (7.3), Production (7.5), and CAPA (8.5.2/8.5.3).
153 
154### Workflow: Individual Audit Execution
155 
1561. Prepare audit plan with scope, criteria, and schedule
1572. Notify auditee minimum 1 week prior
1583. Review procedures and previous audit results
1594. Prepare audit checklist
1605. Conduct opening meeting
1616. Collect evidence through:
162 - Document review
163 - Record sampling
164 - Process observation
165 - Personnel interviews
1667. Classify findings:
167 - Major NC: Absence or breakdown of system
168 - Minor NC: Single lapse or deviation
169 - Observation: Risk of future NC
1708. Conduct closing meeting
1719. Issue audit report within 5 business days
17210. **Validation:** All checklist items addressed; findings supported by evidence; report distributed
173 
174### Auditor Qualification Requirements
175 
176| Criterion | Requirement |
177|-----------|-------------|
178| Training | ISO 13485 awareness + auditor training |
179| Experience | Minimum 1 audit as observer |
180| Independence | Not auditing own work area |
181| Competence | Understanding of audited process |
182 
183### Finding Classification Guide
184 
185| Classification | Criteria | Response Time |
186|----------------|----------|---------------|
187| Major NC | System absence, total breakdown, regulatory violation | 30 days for CAPA |
188| Minor NC | Single instance, partial compliance | 60 days for CAPA |
189| Observation | Potential risk, improvement opportunity | Track in next audit |
190 
191---
192 
193## Process Validation Workflow
194 
195Validate special processes per ISO 13485 Clause 7.5.6.
196 
197### Workflow: Process Validation Protocol
198 
1991. Identify processes requiring validation:
200 - Output cannot be verified by inspection
201 - Deficiencies appear only in use
202 - Sterilization, welding, sealing, software
2032. Form validation team with subject matter experts
2043. Write validation protocol including:
205 - Process description and parameters
206 - Equipment and materials
207 - Acceptance criteria
208 - Statistical approach
2094. Execute IQ: verify equipment installed correctly and document specifications
2105. Execute OQ: test parameter ranges and verify process control
2116. Execute PQ: run production conditions and verify output meets requirements
2127. Write validation report with conclusions
2138. **Validation:** IQ/OQ/PQ complete; acceptance criteria met; validation report approved
214 
215### Validation Documentation Requirements
216 
217| Phase | Content | Evidence |
218|-------|---------|----------|
219| Protocol | Objectives, methods, criteria | Approved protocol |
220| IQ | Equipment verification | Installation records |
221| OQ | Parameter verification | Test results |
222| PQ | Performance verification | Production data |
223| Report | Summary, conclusions | Approval signatures |
224 
225### Revalidation Triggers
226 
227| Trigger | Action Required |
228|---------|-----------------|
229| Equipment change | Assess impact, revalidate affected phases |
230| Parameter change | OQ and PQ minimum |
231| Material change | Assess impact, PQ minimum |
232| Process failure | Full revalidation |
233| Periodic | Per validation schedule (typically 3 years) |
234 
235### Special Process Examples
236 
237| Process | Validation Standard | Critical Parameters |
238|---------|--------------------|--------------------|
239| EO Sterilization | ISO 11135 | Temperature, humidity, EO concentration, time |
240| Steam Sterilization | ISO 17665 | Temperature, pressure, time |
241| Radiation Sterilization | ISO 11137 | Dose, dose uniformity |
242| Sealing | Internal | Temperature, pressure, dwell time |
243| Welding | ISO 11607 | Heat, pressure, speed |
244 
245---
246 
247## Supplier Qualification Workflow
248 
249Evaluate and approve suppliers per ISO 13485 Clause 7.4.
250 
251### Workflow: New Supplier Qualification
252 
2531. Identify supplier category:
254 - Category A: Critical (affects safety/performance)
255 - Category B: Major (affects quality)
256 - Category C: Minor (indirect impact)
2572. Request supplier information:
258 - Quality certifications
259 - Product specifications
260 - Quality history
2613. Evaluate supplier based on:
262 - Quality system (ISO certification)
263 - Technical capability
264 - Quality history
265 - Financial stability
2664. For Category A suppliers:
267 - Conduct on-site audit
268 - Require quality agreement
2695. Calculate qualification score
2706. Make approval decision:
271 - >80: Approved
272 - 60-80: Conditional approval
273 - <60: Not approved
2747. Add to Approved Supplier List
2758. **Validation:** Evaluation criteria scored; qualification records complete; supplier categorized
276 
277### Supplier Evaluation Criteria
278 
279| Criterion | Weight | Scoring |
280|-----------|--------|---------|
281| Quality System | 30% | ISO 13485=30, ISO 9001=20, Documented=10, None=0 |
282| Quality History | 25% | Reject rate: <1%=25, 1-3%=15, >3%=0 |
283| Delivery | 20% | On-time: >95%=20, 90-95%=10, <90%=0 |
284| Technical Capability | 15% | Exceeds=15, Meets=10, Marginal=5 |
285| Financial Stability | 10% | Strong=10, Adequate=5, Questionable=0 |
286 
287### Supplier Category Requirements
288 
289| Category | Qualification | Monitoring | Agreement |
290|----------|---------------|------------|-----------|
291| A - Critical | On-site audit | Annual review | Quality agreement |
292| B - Major | Questionnaire | Semi-annual review | Quality requirements |
293| C - Minor | Assessment | Issue-based | Standard terms |
294 
295### Supplier Performance Metrics
296 
297| Metric | Target | Calculation |
298|--------|--------|-------------|
299| Accept Rate | >98% | (Accepted lots / Total lots) × 100 |
300| On-Time Delivery | >95% | (On-time / Total orders) × 100 |
301| Response Time | <5 days | Average days to resolve issues |
302| Documentation | 100% | (Complete CoCs / Required CoCs) × 100 |
303 
304---
305 
306## QMS Process Reference
307 
308For detailed requirements and audit questions for each ISO 13485:2016 clause, see [iso13485-clause-requirements.md](references/iso13485-clause-requirements.md).
309 
310### Management Review Required Inputs (Clause 5.6.2)
311 
312| Input | Source | Prepared By |
313|-------|--------|-------------|
314| Audit results | Internal and external audits | QA Manager |
315| Customer feedback | Complaints, surveys | Customer Quality |
316| Process performance | Process metrics | Process Owners |
317| Product conformity | Inspection data, NCs | QC Manager |
318| CAPA status | CAPA system | CAPA Officer |
319| Previous actions | Prior review records | QMR |
320| Changes affecting QMS | Regulatory, organizational | RA Manager |
321| Recommendations | All sources | All Managers |
322 
323### Record Retention Requirements
324 
325> **⚠️ STATUS — QMSR transition (effective 2026-02-02):** FDA's Quality Management System Regulation (QMSR) final rule (89 FR 7496) amended 21 CFR Part 820 to **incorporate ISO 13485:2016 by reference** and removed the legacy QSR subsection structure. The section numbers below (820.30/.181/.184/.198) **no longer exist in the CFR** — they are retained only as a familiar index. The current authority for record retention is **ISO 13485:2016 §4.2.5** (retain "for at least the lifetime of the medical device as defined by the organization, but not less than two years"), with records additions in retained **21 CFR 820.35**. Cite the ISO 13485 clauses — not the 820.x numbers — in current compliance documentation.
326 
327| Record Type | Minimum Retention | Current authority under QMSR (legacy QSR shown for index) |
328|-------------|-------------------|------------------|
329| Device Master Record | Life of device + 2 years | ISO 13485 §4.2.3 (medical device file)/§4.2.5 (legacy QSR 820.181, historical) |
330| Device History Record | Life of device + 2 years | ISO 13485 §4.2.5 + 21 CFR 820.35 (legacy QSR 820.184, historical) |
331| Design History File | Life of device + 2 years | ISO 13485 §7.3.10/§4.2.5 (legacy QSR 820.30, historical) |
332| Complaint Records | Life of device + 2 years | ISO 13485 §8.2.2/§4.2.5 + 21 CFR 820.35(b) (legacy QSR 820.198, historical) |
333| Training Records | Employment + 3 years | Best practice |
334| Audit Records | 7 years | Best practice |
335| CAPA Records | 7 years | Best practice |
336| Calibration Records | Equipment life + 2 years | Best practice |
337 
338> **Decision discipline:** This skill's checklists and tools structure QMS conformity assessment — they do not certify ISO 13485 / QMSR compliance. Final compliance determinations and record-retention decisions are yours to make and must be reviewed and signed off by the named QMR; route FDA-specific regulatory-classification questions to Regulatory Affairs and confirm current 21 CFR 820 / ISO 13485:2016 text at fda.gov before relying on any citation here.
339 
340---
341 
342## Decision Frameworks
343 
344### Exclusion Justification (Clause 4.2.2)
345 
346| Clause | Permissible Exclusion | Justification Required |
347|--------|----------------------|------------------------|
348| 6.4.2 | Contamination control | Product not affected by contamination |
349| 7.3 | Design and development | Organization does not design products |
350| 7.5.2 | Product cleanliness | No cleanliness requirements |
351| 7.5.3 | Installation | No installation activities |
352| 7.5.4 | Servicing | No servicing activities |
353| 7.5.5 | Sterile products | No sterile products |
354 
355### Nonconformity Disposition Decision Tree
356 
357```
358Nonconforming Product Identified
359 │
360 ▼
361 Can it be reworked?
362 │
363 Yes──┴──No
364 │ │
365 ▼ ▼
366 Is rework Can it be used
367 procedure as is?
368 available? │
369 │ Yes──┴──No
370 Yes─┴─No │ │
371 │ │ ▼ ▼
372 ▼ ▼ Concession Scrap or
373 Rework Create approval return to
374 per SOP rework needed? supplier
375 procedure │
376 Yes─┴─No
377 │ │
378 ▼ ▼
379 Customer Use as is
380 approval with MRB
381 approval
382```
383 
384### CAPA Initiation Criteria
385 
386| Source | Automatic CAPA | Evaluate for CAPA |
387|--------|----------------|-------------------|
388| Customer complaint | Safety-related | All others |
389| External audit | Major NC | Minor NC |
390| Internal audit | Major NC | Repeat minor NC |
391| Product NC | Field failure | Trend exceeds threshold |
392| Process deviation | Safety impact | Repeated deviations |
393 
394---
395 
396## Tools and References
397 
398### Scripts
399 
400| Tool | Purpose | Usage |
401|------|---------|-------|
402| [qms_audit_checklist.py](scripts/qms_audit_checklist.py) | Generate audit checklists by clause or process | `python qms_audit_checklist.py --help` |
403 
404**Audit Checklist Generator Features:**
405- Generate clause-specific checklists (e.g., `--clause 7.3`)
406- Generate process-based checklists (e.g., `--process design-control`)
407- Full system audit checklist (`--audit-type system`)
408- Text or JSON output formats
409- Interactive mode for guided selection
410 
411### References
412 
413| Document | Content |
414|----------|---------|
415| [iso13485-clause-requirements.md](references/iso13485-clause-requirements.md) | Detailed requirements for each ISO 13485:2016 clause with audit questions |
416| [qms-process-templates.md](references/qms-process-templates.md) | Ready-to-use templates for gap analysis, audit program, document control, CAPA, supplier, training |
417 
418### Quick Reference: Mandatory Documented Procedures
419 
420| Procedure | Clause | Key Elements |
421|-----------|--------|--------------|
422| Document Control | 4.2.3 | Approval, distribution, obsolete control |
423| Record Control | 4.2.4 | Identification, retention, disposal |
424| Internal Audit | 8.2.4 | Program, auditor qualification, reporting |
425| NC Product Control | 8.3 | Identification, segregation, disposition |
426| Corrective Action | 8.5.2 | Root cause, implementation, verification |
427| Preventive Action | 8.5.3 | Risk identification, implementation |
428 
429---
430 
431## Related Skills
432 
433| Skill | Integration Point |
434|-------|-------------------|
435| [quality-manager-qmr](../quality-manager-qmr/) | Management review, quality policy |
436| [capa-officer](../capa-officer/) | CAPA system management |
437| [qms-audit-expert](../qms-audit-expert/) | Advanced audit techniques |
438| [quality-documentation-manager](../quality-documentation-manager/) | DHF, DMR, DHR management |
439| [risk-management-specialist](../risk-management-specialist/) | ISO 14971 integration |
440 

Discussion

Alternatives

Also in Developer docsSee all 533 in Development →