Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 13485 Mandatory Documents — ISO 13485:2016 medical device quality management

ISO 13485 Mandatory Documents and Records Explained

ISO 13485 mandatory documents are the ones the standard names explicitly, and the list is shorter than most people fear. Unlike
ISO 9001:2015, which deliberately avoided prescribing a document set, ISO 13485:2016 is specific
— and it asks for two things ISO 9001 dropped entirely.

The two documents ISO 9001 no longer requires

A quality manual is mandatory. Clause 4.2.2 requires one by name, covering the
scope of the QMS including justification for any exclusions, the documented procedures or references
to them, and a description of the interaction between processes. ISO 9001:2015 removed this
requirement; ISO 13485 kept it.

A medical device file is mandatory. Clause 4.2.3 requires a file for each device
type or family containing the device description and intended use, labelling, specifications,
manufacturing and monitoring procedures, installation and servicing requirements as applicable. For
many organisations this is the clause that reframes documentation from “policies” to “evidence tied
to a specific product”.

ISO 13485 mandatory documents: the documented procedures

These are the ones where ISO 13485 uses the phrase “documented procedure”, meaning it must be
established, documented, implemented and maintained:

  • Control of documents (4.2.4) and control of records (4.2.5)
  • Management review (5.6.1)
  • Risk management throughout product realization (7.1)
  • Design and development (7.3), including planning, inputs, outputs, review, verification,
    validation, transfer, change control and the design and development file
  • Purchasing and supplier evaluation (7.4)
  • Production and service provision, including cleanliness, installation, servicing, sterile
    device processes and validation of processes (7.5)
  • Traceability (7.5.9), with additional requirements for implantable devices
  • Preservation of product (7.5.11)
  • Feedback (8.2.1) and complaint handling (8.2.2)
  • Reporting to regulatory authorities (8.2.3)
  • Internal audit (8.2.4)
  • Control of nonconforming product (8.3), including rework and advisory notices
  • Corrective action (8.5.2) and, still separately, preventive action (8.5.3)

Note the last point. ISO 9001:2015 folded preventive action into risk-based thinking and dropped
it as a clause. ISO 13485 retains preventive action as a distinct documented procedure,
and auditors expect records that are genuinely preventive rather than reactive.

Every document on this list, already drafted.

The ISO 13485 Toolkit ships the quality manual, medical device file structure, and each documented procedure the standard names — editable Word and Excel, mapped clause by clause.

Explore the ISO 13485 Toolkit →

ISO 13485 mandatory documents that are records

Records are the evidence that procedures ran. The commonly audited set includes management review
minutes, competence and training records, design and development records for each project,
supplier evaluation and re-evaluation records, process validation records, calibration records,
complaint and feedback records, regulatory reporting records, internal audit reports,
nonconformity and CAPA records, and traceability records including distribution.

For sterile devices, add sterilisation process records. For implantable devices, add the extended
traceability records the standard requires including personnel performing critical operations.

How long records must be kept

Clause 4.2.5 sets a rule people frequently get wrong. Records must be retained for
at least the lifetime of the medical device as defined by the organisation, or as
specified by applicable regulatory requirements, but not less than two years from release of
the device
.

Three things follow. You define the device lifetime, and you must be able to justify the
figure. Two years is a floor, not a target — for a device with a ten-year
service life, ten years is the starting point. And regulatory requirements can be longer: EU MDR and
FDA expectations frequently exceed the ISO minimum, and the longest applicable period wins.

Record the retention period per record type in your control of records procedure, with the
reasoning. “Seven years” with no basis is a finding waiting to happen.

Scope exclusions and non-applicability

ISO 13485 allows exclusion only of clause 7 requirements that do not apply to your activity
— design and development (7.3) is the common one for contract manufacturers. Exclusions must be
justified in the quality manual. Requirements in clauses 4, 5, 6 and 8 cannot be excluded. Auditors
read the justification carefully; “not applicable” without reasoning is a finding.

How many ISO 13485 mandatory documents are enough

The standard repeatedly says documentation should be proportionate to the risk of the device and
the complexity of the process. In practice, the test an auditor applies is whether a competent
person could carry out the activity consistently from what is written, and whether the records
prove it happened. Volume is not the measure — retrievability and traceability are.

If you want to see the format before committing, several of these documents are available as
free ISO 13485 templates.

References

More on ISO 13485

All of these are covered by the ISO 13485 Toolkit, or try the free ISO 13485 templates first.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.