What documents does ISO 13485 require?
ISO 13485:2016 · Documentation requirements §4.2
Quick answer
ISO 13485 requires a quality manual, approximately 12 mandatory documented procedures, around 15 defined record types, and a medical device file per product type. The documentation pyramid runs from policy down through procedures, work instructions, and records — with the medical device file as a product-specific thread running through all of them.
The documentation pyramid
ISO 13485 documentation is structured in layers. At the top sits the quality policy and quality manual (or equivalent top-level document). Below that sit documented procedures describing how processes are conducted. Work instructions provide step-by-step operational detail. At the base are records — the evidence that activities were carried out as required. Cutting across all layers is the medical device file: a product-specific collection of documents demonstrating conformity of each device.
Mandatory documented procedures
ISO 13485:2016 explicitly requires documented procedures for the following activities:
| Procedure | Clause |
|---|---|
| Document control | 4.2.4 |
| Records control | 4.2.5 |
| Feedback and post-market surveillance | 8.2.1 |
| Complaint handling | 8.2.1 |
| Reporting to regulatory authorities (vigilance) | 8.2.3 |
| Internal audit | 8.2.4 |
| Control of nonconforming product | 8.3 |
| Corrective action (CAPA) | 8.5.2 |
| Preventive action | 8.5.3 |
| Design and development (if applicable) | 7.3 |
| Purchasing / supplier control | 7.4 |
| Returned product handling | 7.5.8 |
Mandatory records
Records provide objective evidence that the QMS is operating as intended. The standard requires specific records to be maintained:
| Record type | Clause | Minimum retention |
|---|---|---|
| Management review records | 5.6 | Product lifetime + 2 years (min 5 years) |
| Competence and training records | 6.2 | Product lifetime + 2 years |
| Infrastructure maintenance records | 6.3 | Product lifetime + 2 years |
| Work environment monitoring records | 6.4 | Product lifetime + 2 years |
| Design and development records (DHF) | 7.3 | Product lifetime + 2 years (min 5 years) |
| Supplier evaluation and approval records | 7.4 | Product lifetime + 2 years |
| Device history records (DHR / batch records) | 7.5.1 | Product lifetime + 2 years (min 5 years) |
| Traceability records | 7.5.3 | Product lifetime + 2 years |
| Customer property records | 7.5.10 | Product lifetime + 2 years |
| Calibration records | 7.6 | Product lifetime + 2 years |
| Internal audit records | 8.2.4 | Product lifetime + 2 years |
| Nonconforming product records | 8.3 | Product lifetime + 2 years |
| CAPA records | 8.5.2 / 8.5.3 | Product lifetime + 2 years |
| Complaint handling records | 8.2.1 | Product lifetime + 2 years (min 5 years) |
| Vigilance / MDR reporting records | 8.2.3 | Product lifetime + 2 years |
The Medical Device File (clause 4.2.3)
Clause 4.2.3 requires each manufacturer to establish and maintain a medical device file (MDF) for each type or family of medical devices. The MDF is not a single document — it is an index or collection that references or contains all documentation demonstrating that the device meets regulatory requirements. It is the ISO 13485 equivalent of the FDA Design History File (DHF) and the EU MDR Technical Documentation.
The MDF typically contains or references:
- Device description and intended purpose
- Design inputs and outputs
- Design verification and validation records
- Risk management file (per ISO 14971)
- Clinical evaluation or performance evaluation
- Labelling and Instructions for Use (IFU)
- Manufacturing specifications and procedures
- Post-market surveillance data
Document control (clause 4.2.4)
Every document within the QMS must be controlled. Document control means: approval before issue, review and update as necessary, identification of revision status, availability at point of use, and management of obsolete documents (withdrawal or labelling). External documents (regulatory guidance, referenced standards, customer specifications) must also be identified and their distribution controlled.
Electronic document management systems (EDMS) are widely used. If software is used to manage QMS documents, the software itself must be validated per clause 4.1.6 before use.
Records retention
ISO 13485:2016 states that records must be retained for at least the greater of: (a) the lifetime of the device as defined by the organisation, plus 2 years; or (b) the minimum period specified by applicable regulatory requirements (often 5 years for non-implantable devices, 15 years for implantables in the EU under MDR). Country-specific requirements may override the standard's minimum.
Electronic records
Electronic records are acceptable under ISO 13485 provided the electronic system ensures records remain legible, identifiable, and retrievable throughout the retention period. For organisations selling into the US market, FDA 21 CFR Part 11 governs the use of electronic records and electronic signatures, requiring audit trails, access controls, and system validation. EU Annex 11 to GMP provides equivalent guidance for EU-based organisations.