7 Core Quality Management System (QMS) Documents Every Medical Device Manufacturer Needs

A compliant Quality Management System (QMS) forms the foundation of every successful medical device manufacturer. While ISO 13485 contains numerous documentation requirements, several core documents underpin regulatory compliance, product quality and continual improvement. In this guide, we explain the seven essential QMS documents every manufacturer should establish and how they support compliance with ISO 13485, the EU MDR and the IVDR.
7 Essential QMS Documents for Medical Device Manufacturers

Why QMS Documentation Matters

Developing a Quality Management System is one of the first and most important milestones for any medical device manufacturer.

Whether you are preparing your first ISO 13485 certification, developing technical documentation for CE marking or scaling your organisation internationally, your Quality Management System provides the framework that ensures products are consistently designed, manufactured and monitored to meet regulatory requirements.

However, many organisations—particularly start-ups and first-time manufacturers—quickly discover that implementing a QMS involves far more than writing a collection of procedures.

Every document should work together to demonstrate that quality is embedded throughout the entire product lifecycle.

Your Quality Management System should support:

  • Design and development
  • Risk management
  • Supplier control
  • Manufacturing
  • Validation
  • Complaint handling
  • Post-Market Surveillance
  • Corrective and Preventive Actions (CAPA)
  • Internal audits
  • Continual improvement

While every organisation’s documentation will differ depending on the complexity of its products and processes, several documents form the core of almost every compliant medical device Quality Management System.

In this article we explore the seven most important documents and explain why each plays a critical role in achieving regulatory compliance.

Infographic showing the seven core Quality Management System (QMS) documents required for ISO 13485 compliance, including the Quality Manual, QMS Procedures, Risk Management File, Design and Development Procedure, Validation Procedure, CAPA Procedure and Internal Audit Procedure.

1. Quality Manual

The Quality Manual serves as the cornerstone of your Quality Management System. Although ISO 13485:2016 no longer explicitly requires organisations to maintain a formal Quality Manual in the same way as previous editions, many manufacturers continue to use one because it provides a clear overview of how their Quality Management System is structured and implemented.

A well-written Quality Manual helps employees, auditors and regulatory authorities understand how your organisation meets the requirements of ISO 13485 and how individual procedures fit together.

Rather than containing detailed work instructions, the Quality Manual typically provides a high-level description of your Quality Management System, including:

  • The scope of the Quality Management System
  • The products and services covered
  • The quality policy and quality objectives
  • Organisational structure and responsibilities
  • References to supporting procedures
  • The interaction between key QMS processes
  • Exclusions and justifications where applicable

For many organisations, the Quality Manual also acts as a useful roadmap during ISO 13485 certification audits and regulatory inspections, allowing auditors to quickly understand how documentation is organised.

One common mistake is attempting to include every procedure within the Quality Manual itself. Instead, the document should direct readers to the appropriate controlled procedures, work instructions and records.

An effective Quality Manual should remain concise, easy to navigate and aligned with the current version of your Quality Management System.

As your organisation grows, introducing new products, manufacturing processes or international regulatory markets, the Quality Manual should be reviewed to ensure it continues to accurately reflect your Quality Management System.

2. Document and Record Control Procedure

No Quality Management System can function effectively without robust document control.

Medical device manufacturers generate hundreds, and often thousands, of controlled documents throughout the product lifecycle. Without a structured process for managing these documents, organisations quickly lose confidence that employees are working from the correct versions.

A Document and Record Control Procedure establishes how documents are:

  • Created
  • Reviewed
  • Approved
  • Issued
  • Revised
  • Distributed
  • Archived
  • Withdrawn when obsolete

It also defines how quality records are maintained to demonstrate compliance.

Examples of controlled records include:

  • Training records
  • Internal audit reports
  • CAPA records
  • Supplier evaluations
  • Validation reports
  • Risk Management Files
  • Clinical Evaluation Reports
  • Design Review records

One of the most common findings during ISO 13485 audits is the use of uncontrolled or obsolete documentation.

For example, an employee may be following an outdated work instruction while engineering has already released a revised version.

Similarly, organisations sometimes fail to retain sufficient historical records to demonstrate compliance during regulatory inspections.

A well-designed document control process ensures that every employee accesses the latest approved documentation while maintaining complete revision history and traceability.

This not only supports ISO 13485 certification but also significantly reduces technical documentation inconsistencies during MDR and IVDR conformity assessments.

3. Risk Management File

Risk Management sits at the heart of every compliant medical device Quality Management System.

Rather than being treated as a standalone regulatory exercise, Risk Management should influence decisions throughout design, manufacturing, clinical evaluation, supplier management and post-market surveillance.

Under ISO 14971, manufacturers are expected to establish, document, implement and maintain a systematic process for identifying hazards, estimating and evaluating risks, implementing risk control measures and monitoring their ongoing effectiveness.

The Risk Management File typically includes:

  • Risk Management Plan
  • Hazard Identification
  • Risk Analysis
  • Risk Evaluation
  • Risk Control Measures
  • Residual Risk Evaluation
  • Benefit-Risk Analysis
  • Risk Management Report

Importantly, the Risk Management File should not remain static.

As new information becomes available through complaints, Post-Market Surveillance, PMCF activities, customer feedback or scientific literature, identified risks should be reviewed and updated where appropriate.

One of the most frequent regulatory observations occurs when the Risk Management File no longer reflects the latest Clinical Evaluation or Post-Market Surveillance findings.

Strong organisations maintain complete traceability between Risk Management, Clinical Evaluation, Biological Evaluation and Technical Documentation, ensuring every identified risk is appropriately monitored throughout the product lifecycle.

4. Design and Development Procedure

For most medical device manufacturers, design and development represents the largest and most complex element of the Quality Management System.

ISO 13485 requires manufacturers to establish documented procedures that ensure medical devices are designed in a controlled, systematic and traceable manner. These procedures help demonstrate that devices consistently meet user needs, intended use and applicable regulatory requirements before they reach the market.

A Design and Development Procedure typically defines how the organisation manages:

  • Design planning
  • Design inputs
  • Design outputs
  • Design reviews
  • Design verification
  • Design validation
  • Design transfer
  • Design changes
  • Design history records

Each stage should generate objective evidence demonstrating that design activities have been completed appropriately.

For example, design inputs should clearly define user needs, intended purpose, regulatory requirements and performance expectations before development begins. Design outputs should then demonstrate that those requirements have been successfully translated into product specifications.

Throughout development, formal design reviews provide opportunities to identify issues early, while verification confirms that design outputs meet the design inputs. Validation then demonstrates that the finished device satisfies the intended user needs under actual or simulated conditions of use.

Design changes also require careful control.

Even seemingly minor modifications can affect safety, performance, usability or regulatory compliance. A documented change control process ensures every modification is appropriately assessed, reviewed, verified and approved before implementation.

One of the most common audit findings occurs when manufacturers cannot demonstrate traceability between design inputs, verification activities, validation evidence and final design outputs.

Maintaining this traceability not only supports ISO 13485 certification but also significantly strengthens MDR and IVDR technical documentation.

5. Corrective and Preventive Action (CAPA) Procedure

No Quality Management System is perfect.

Despite careful planning, issues will inevitably arise during design, manufacturing, supplier management or post-market use. What distinguishes a mature Quality Management System is not the absence of problems but the organisation’s ability to investigate them systematically and prevent recurrence.

This is the purpose of Corrective and Preventive Action (CAPA).

A CAPA procedure establishes how quality issues are:

  • Identified
  • Reported
  • Investigated
  • Root causes determined
  • Corrective actions implemented
  • Preventive actions identified
  • Effectiveness verified
  • Officially closed

Sources of CAPAs often include:

  • Customer complaints
  • Internal audits
  • Supplier non-conformities
  • Production deviations
  • Risk Management reviews
  • Post-Market Surveillance
  • Vigilance activities
  • Management Reviews

One of the most common weaknesses identified during certification audits is treating CAPA as a simple corrective action log.

Instead, auditors expect manufacturers to investigate why problems occurred in the first place.

Root cause analysis tools such as the 5 Whys, Fishbone Diagrams or Fault Tree Analysis are commonly used to identify systemic causes rather than simply correcting individual incidents.

Equally important is verifying that corrective actions have actually been effective.

Without documented evidence demonstrating improved performance, a CAPA cannot truly be considered complete.

An effective CAPA system drives continual improvement throughout the organisation and provides valuable evidence that quality issues are actively managed before they escalate into regulatory concerns.

6. Internal Audit Procedure

Internal audits provide manufacturers with one of the most effective opportunities to identify weaknesses before they become findings during external certification audits or regulatory inspections.

Rather than viewing internal audits as a compliance exercise, organisations should use them as an independent assessment of whether their Quality Management System continues to operate effectively.

A documented Internal Audit Procedure should define:

  • Audit planning
  • Audit frequency
  • Auditor competence
  • Audit scope
  • Audit methodology
  • Reporting requirements
  • Non-conformity grading
  • Follow-up activities
  • Verification of corrective actions

Importantly, internal auditors should remain independent of the activities they are auditing wherever practical.

This helps ensure findings remain objective and unbiased.

During audits, evidence should be gathered through:

  • Document review
  • Interviews
  • Process observation
  • Record sampling
  • Objective evidence collection

Audit findings frequently identify opportunities to improve:

  • Document control
  • Training
  • Risk Management
  • Design controls
  • Supplier management
  • Validation activities
  • Complaint handling
  • CAPA effectiveness

Strong organisations treat audit findings as opportunities for continual improvement rather than simply issues requiring correction.

By identifying documentation inconsistencies before an external audit, manufacturers significantly reduce the likelihood of receiving major non-conformities during ISO 13485 certification or MDR and IVDR conformity assessments.

7. Management Review Procedure

A Quality Management System cannot remain effective without active leadership.

ISO 13485 requires top management to regularly review the suitability, adequacy and effectiveness of the Quality Management System to ensure it continues to support organisational objectives and regulatory compliance.

Management Review provides senior leadership with an opportunity to evaluate whether the Quality Management System remains fit for purpose.

Typical Management Review inputs include:

  • Internal audit results
  • Customer feedback
  • Complaints and vigilance activities
  • Post-Market Surveillance findings
  • CAPA performance
  • Supplier performance
  • Process performance
  • Product conformity
  • Risk Management updates
  • Regulatory changes
  • Resource requirements
  • Opportunities for improvement

Following review, management should document decisions relating to:

  • Quality objectives
  • Resource allocation
  • Process improvements
  • Risk mitigation
  • Product improvements
  • Training needs
  • Strategic priorities

One common misconception is that Management Review should only occur immediately before certification audits.

In reality, it should be an ongoing strategic process that demonstrates leadership commitment to maintaining an effective Quality Management System.

Well-documented Management Reviews provide valuable evidence that senior management remains actively engaged in quality, regulatory compliance and continual improvement.

Bringing Your Quality Management System Together

While these seven documents form the foundation of many medical device Quality Management Systems, they should never be viewed as isolated procedures.

A truly effective QMS is built on the interaction between processes.

For example:

  • Risk Management informs Design and Development.
  • Design outputs support Technical Documentation.
  • Internal Audits identify opportunities for CAPA.
  • CAPAs improve manufacturing and supplier controls.
  • Post-Market Surveillance feeds back into Risk Management.
  • Management Review evaluates the effectiveness of the entire system.

When these processes operate together, manufacturers create a Quality Management System that not only satisfies ISO 13485 but also supports compliance with the EU MDR, IVDR and other international regulatory frameworks.

Rather than simply maintaining documentation for audit purposes, organisations should focus on creating a Quality Management System that consistently delivers safe, effective and high-quality medical devices throughout the entire product lifecycle.

Building a Strong Foundation for Regulatory Compliance

Implementing an effective Quality Management System is not about creating documentation simply to satisfy an auditor or achieve ISO 13485 certification.

The true purpose of a QMS is to establish a structured framework that consistently delivers safe, effective and compliant medical devices throughout their entire lifecycle.

The seven core documents discussed in this article provide the foundation for that framework.

Together they help manufacturers:

  • Establish clear organisational responsibilities.
  • Maintain control over documentation and records.
  • Manage product risks throughout the lifecycle.
  • Develop medical devices using structured design controls.
  • Investigate quality issues and drive continual improvement.
  • Monitor the effectiveness of the Quality Management System.
  • Demonstrate leadership commitment to quality and regulatory compliance.

While every organisation’s documentation will differ depending on the complexity of its products, manufacturing processes and regulatory markets, the principles remain the same.

A well-implemented Quality Management System should not be viewed as a collection of standalone procedures.

Instead, each document should support the others, creating a fully integrated system that links quality management, risk management, design controls, post-market surveillance and continual improvement.

As regulatory expectations continue to evolve under ISO 13485, the EU MDR and the IVDR, manufacturers that invest in robust QMS documentation today will be significantly better prepared for certification audits, Notified Body reviews and future regulatory inspections.

Ultimately, a mature Quality Management System not only supports compliance—it helps organisations consistently deliver safer medical devices, improve operational efficiency and build confidence among regulators, customers and patients alike.

How Patient Guard Can Help

Whether you are implementing your first Quality Management System or improving an existing ISO 13485-certified QMS, Patient Guard can provide practical regulatory support tailored to your organisation.

Our experienced consultants help manufacturers with:

  • ISO 13485 Quality Management System implementation
  • Quality Manual development
  • QMS procedures and process mapping
  • Risk Management (ISO 14971)
  • Design and Development documentation
  • Validation planning and execution
  • CAPA system implementation
  • Internal Audits
  • Management Review support
  • Technical Documentation
  • Clinical Evaluation
  • Biological Evaluation
  • Post-Market Surveillance
  • MDR and IVDR compliance

From innovative start-ups to established global manufacturers, we help organisations build practical Quality Management Systems that support both regulatory compliance and long-term business growth.

Frequently Asked Questions

ISO 13485 requires manufacturers to establish and maintain documented procedures across a wide range of quality processes. While documentation requirements vary depending on the organisation and the nature of its products, core documents typically include a Quality Manual, Document Control Procedure, Risk Management documentation, Design and Development procedures, CAPA procedures, Internal Audit procedures and Management Review records.

Unlike previous editions of the standard, ISO 13485:2016 does not explicitly require a formal Quality Manual. However, many manufacturers continue to maintain one because it provides a useful overview of the Quality Management System and helps employees, auditors and regulatory authorities understand how quality processes interact.

A Quality Management System describes how an organisation consistently designs, manufactures and monitors medical devices. Technical Documentation focuses on demonstrating that a specific medical device complies with applicable regulatory requirements, including safety, performance and clinical evidence.

There is no fixed review period specified within ISO 13485. Manufacturers should review procedures whenever significant changes occur or at planned intervals defined within their document control process to ensure documentation remains accurate, effective and compliant.

Document control ensures employees always work from the latest approved procedures while maintaining complete revision history and traceability. Effective document control reduces errors, supports regulatory compliance and helps demonstrate conformity during certification audits and regulatory inspections.

Risk Management should be fully integrated within the Quality Management System rather than operating as a separate activity. Risk assessments influence design decisions, verification, validation, Clinical Evaluation, Post-Market Surveillance and continual improvement throughout the medical device lifecycle.

Yes. Although the complexity of documentation may differ, start-ups developing medical devices should establish a Quality Management System as early as possible. Implementing quality processes during product development is significantly easier than attempting to introduce them immediately before certification or regulatory submission.

Yes. Patient Guard supports medical device manufacturers with ISO 13485 implementation, Quality Management System development, Internal Audits, Risk Management, Technical Documentation, Clinical Evaluation and ongoing regulatory compliance for UK, EU and international markets.

David Small BSc (Hons), MSc, MTOPRA

David Small BSc (Hons), MSc, MTOPRA

Reviewed by
David Small, BSc (Hons), MSc, MTOPRA
Founder & CEO |
20+ years in medical device regulatory affairs,  MDR/IVDR compliance and quality systems.

Patient Guards Recent Posts

10 Common Technical Documentation Deficiencies Found During EU MDR and IVDR Notified Body Reviews

10 Common Technical Documentation Deficiencies Found During EU MDR and IVDR Notified Body Reviews

Preparing technical documentation for EU MDR or IVDR certification is only half the challenge. Successfully passing a Notified Body review depends on demonstrating consistency across your Quality Management System, Clinical Evaluation, Risk Management, Biological Evaluation, Performance Evaluation and Post-Market Surveillance activities. Discover ten of the most common technical documentation deficiencies identified during MDR and IVDR conformity assessments—and learn how to reduce the likelihood of costly review cycles and certification delays.

Read More »
Patient Guard EU Authorised Representative Services

EU Authorised Representative Services for Medical Device & IVD Manufacturers

Selling medical devices or IVDs in Europe? If your company is based outside the EU, appointing an EU Authorised Representative (EC Rep) is a legal requirement under EU MDR 2017/745 and IVDR 2017/746. Patient Guard provides expert EU Authorised Representative services, EUDAMED support, regulatory guidance, and ongoing compliance management to help manufacturers access and maintain the European market with confidence.

Read More »

Patient Guards Related Services

Patient Guards Regulatory Tools

Need Training?

Do you need training on Quality Management Systems or EU MDR/ EU IVDR? then check out our training courses.

Share this guide:

Most Popular

10 Common Technical Documentation Deficiencies Found During EU MDR and IVDR Notified Body Reviews

Preparing technical documentation for EU MDR or IVDR certification is only half the challenge. Successfully passing a Notified Body review depends on demonstrating consistency across your Quality Management System, Clinical Evaluation, Risk Management, Biological Evaluation, Performance Evaluation and Post-Market Surveillance activities. Discover ten of the most common technical documentation deficiencies identified during MDR and IVDR conformity assessments—and learn how to reduce the likelihood of costly review cycles and certification delays.

Read More »

EU Authorised Representative Services for Medical Device & IVD Manufacturers

Selling medical devices or IVDs in Europe? If your company is based outside the EU, appointing an EU Authorised Representative (EC Rep) is a legal requirement under EU MDR 2017/745 and IVDR 2017/746. Patient Guard provides expert EU Authorised Representative services, EUDAMED support, regulatory guidance, and ongoing compliance management to help manufacturers access and maintain the European market with confidence.

Read More »
patient guard
Patient Guard

Sign up to our newsletter

Be the first to hear industry news and how Patient Guard can help you.

Get the latest updates on medical device regulation

Sign up to our newsletter and we’ll deliver news and insights straight to your inbox.
Patient Guard Regulatory Affairs and Quality Assurance

Get the Medical Device Technical Checklist

Thank you! The checklist is now ready to download.

checklist-tablet