
ISO 13485
ISO 13485 medical device quality management consulting
ISO 13485 consulting helps medical device designers, manufacturers and related suppliers align quality processes with their responsibilities throughout the product lifecycle and applicable requirements. Vosurein reviews the scope, existing processes and evidence to assign responsibilities, implement the system and support internal reviews.
Discuss your ISO 13485 medical device quality management needs
For Your Business
Who this service is for and when to start
Medical device design, manufacturing, and related supply service organizations. When documents and on-site practices are inconsistent, outsourcing responsibilities are unclear, or changes and traceability have gaps, the first step is to assess gaps and prioritize tasks.
The Challenge
Common challenges faced by businesses
If drawings reflect a design change but procurement specifications, inspection methods or contract manufacturers still use an older version, the product and its records can diverge. Another common problem is treating complete documentation as proof of completed validation, without considering product risk, process capability and regulatory responsibilities.
Our Approach
Methods and applicable requirements
The adopted version is ISO 13485:2016. Version history: 2003 version (to be read along with errata when applicable); 2016 is the third edition.
This standard focuses on the quality management of medical devices and related services and must align with the organization’s roles in design, production, installation, or service. Regulatory and customer requirements, product risks, and process validation must have actual evidence; system certification does not mean each product is approved for market release.
The following consulting tasks can be arranged to suit your needs.
Current-state and gap analysis
Review products, organisational roles, sites, customer requirements and gaps in the management system.
Documents and responsibilities
Organize procedures, records, versions, and change management.
Design and risk processes
Based on the organization’s design responsibilities, check how design reviews, verification, validation, transfer and risk records connect.
Procurement and outsourcing control
Plan supplier evaluation, quality responsibilities, acceptance, and change notifications.
Production and traceability
Review operations, equipment, measurements, identification, traceability, and release processes.
Process and software validation arrangements
Identify what requires validation, who is responsible and what evidence is needed. Agree the technical work separately for each project.
Feedback and improvement
Connect customer complaints, nonconformities, corrective/preventive actions, and applicable reporting processes.
Training and internal review
Support pilot operation, internal audits, management review and certification preparation.
Process
Consulting scope and process
Review products and regulatory roles
Define the system scope according to the product, target market, and design/manufacturing roles, and confirm which regulations and customer requirements need to correspond to existing quality procedures.
Organize design, procurement, and risk procedures
Clarify how design changes are communicated to procurement, production, and inspection, organize supplier quality responsibilities, and ensure that risk data remains connected to relevant reviews.
Review production traceability and validation evidence
Select batches to trace raw materials, processes, inspections, and release records, review evidence and responsibilities for validation items, and list gaps that need professional execution.
Complaint handling, improvement and internal audits
Link customer complaints, non-conformities, and corrective measures; confirm traceability and change control through internal audits; then arrange management reviews and preparation for external assessments.
Preparation
What documents do companies need to prepare?
- Product roles: Device category, target market, site, and design responsibility.
- Quality system: Procedures, risk files, design, and change records.
- Manufacturing evidence: Suppliers, batches, inspections, release, and validation data.
- Feedback and improvement: Customer complaints, non-conformities, notifications, and corrective actions.
For the initial discussion, you can provide a summary. Handle customer, personal and confidential business information within the necessary scope and agreed access permissions.
Project Planning
Estimating time and cost
Evaluation requires knowing the product category, design responsibility, location, and target market first. When process or software validation evidence is insufficient, technical work will impact the overall schedule.
Quality system guidance and product testing, regulatory registration, professional validation, and third-party certification are agreed separately; market approval is determined by the applicable procedures in each market.
FAQ
Frequently asked questions
Does medical device system certification equal product market access?
No. Product classification, target market, registration, testing, and regulatory requirements must be checked separately; an ISO certificate cannot be regarded as sufficient evidence for market access in all markets.
Can existing systems and records be reused?
You can first review existing products, processes, design responsibilities, target markets, suppliers, and quality records, confirm the applicable period, scope, and quality of evidence, and then fill the gaps; rewriting all documents is not a prerequisite for implementation.
Is it sufficient to only record the quantity of returned goods for customer complaints?
It is still necessary to evaluate the causes, affected scope, and follow-up measures based on the product and event situation, and link to the applicable reporting process, so that quality feedback can return to risk and production management.
How are consulting and third-party certification responsibilities divided?
Vosurein supports system implementation and preparation but does not issue third-party certificates. Confirm the applicable certification scheme, accreditation scope, fees and schedule separately. A certificate does not constitute product approval or proof of compliance with every regulation.
Can ISO 9001 documents be used as a direct substitute?
Shared procedures such as document control may be reused. However, check medical device regulations, risk management, traceability and validation responsibilities individually; replacing the standard’s name is not enough.
Which version should be confirmed before implementation?
This service uses ISO 13485:2016, the third edition. The previous edition was published in 2003, with applicable corrigenda read alongside it. For implementation or transition, confirm the edition and transition arrangements required by the customer and assessment scheme. Publication of a standard does not itself establish the company’s transition deadline.
Related
Related services and enquiries
Please provide the industry, activities, locations, main requirements, and expected completion time.Contact Vosurein
Content checked: . Applicable versions and requirements depend on the company’s circumstances.
Let's Talk
Start a conversation about your needs.
Tell us how the work is done today and when you hope to finish,
so we can agree the scope and way of working together.
Blog
Sustainability and AI insights
Start with understanding,
and see where change can lead.

