4.2.1 and 4.2.2: the documented QMS and the mandatory quality manual
Clause 4.2.1 requires QMS documentation to include the quality policy and quality objectives, a quality manual, documented procedures and records required by the standard, documents the organization determines are needed to ensure effective planning, operation and control of its processes, and any other documentation specified by applicable regulatory requirements.
Clause 4.2.2 then makes something explicit that ISO 9001:2015 no longer requires by name: a documented quality manual. The manual must include, or reference, the scope of the QMS (with justification for any exclusion or non-application of requirements, which under ISO 13485:2016 may apply to aspects of Clauses 6, 7 and 8 — Clauses 4 and 5 themselves cannot be excluded), the documented procedures or reference to them, and a description of the interaction between QMS processes. In practice, the quality manual is the map an auditor uses to navigate the rest of the system — it is the document that ties policy, procedures and process interaction together into one coherent reference.
4.2.3: the medical device file
This is one of ISO 13485's clearest departures from ISO 9001. Clause 4.2.3 requires the organization to establish and maintain a file for each medical device type or family, containing or referencing documents generated to demonstrate conformity to the standard and compliance with applicable regulatory requirements. In practice this file typically references or contains:
- General description of the device, intended use/purpose, and labeling, including instructions for use.
- Specifications for the product.
- Specifications or procedures for manufacturing, packaging, storage, handling and distribution.
- Procedures for measuring and monitoring.
- Requirements for installation, where applicable.
- Procedures for servicing, where applicable.
ISO 9001 has no equivalent concept — it has no notion of a per-product regulatory file, because it is not designed around a specific regulated product category. The medical device file is effectively the technical backbone that regulatory submissions and design history files build on.
4.2.4 and 4.2.5: control of documents and control of records
Both ISO 9001 and ISO 13485 require document and record control, but ISO 13485 is markedly more prescriptive on the mechanics:
- Review and approval before issue, with a defined approval authority for each document.
- Identification of changes and the current revision status of documents, so that superseded content cannot be mistaken for current.
- Retention of at least one obsolete controlled copy for a defined period — the standard explicitly calls out retaining obsolete documents, which ISO 9001 does not require in the same way, because a manufacturer may need to reconstruct exactly what specification or procedure was in force when a specific device or batch was produced.
- Records must remain legible, readily identifiable and retrievable, with controls for identification, storage, protection, retrieval, retention and disposition defined in a documented procedure.
On retention periods specifically: ISO 13485 requires records to be retained for at least the lifetime of the medical device as defined by the organization, but not less than two years from the date of release of the product by the organization, or as specified by applicable regulatory requirements — whichever is longer. What "lifetime of the device" means in practice varies significantly by product risk classification, expected clinical use and the specific regulatory regime the device is placed under, so a manufacturer needs to determine and justify the applicable retention period for each product family rather than assume a single fixed number of years applies across the board.
Why ISO 13485's documentation bar sits above ISO 9001's
| Documentation element |
ISO 9001:2015 |
ISO 13485:2016 |
| Quality manual |
Not explicitly required by name |
Explicitly mandatory, with defined minimum content |
| Per-product file |
No equivalent requirement |
Medical device file mandatory per device type/family |
| Obsolete document retention |
Left to the organization's discretion |
Explicitly required to retain at least one obsolete copy |
| Record retention period |
Not specified by the standard itself |
Tied to device lifetime and a defined regulatory minimum |
| Regulatory documentation |
Not addressed |
Explicit requirement to identify and document applicable regulatory requirements |
The reasoning behind the gap is straightforward: ISO 9001 is a generic customer-satisfaction and process-effectiveness standard applicable to any sector, whereas ISO 13485 exists specifically to support consistent design, production and post-market control of products that can affect patient health. Every extra documentation requirement in clause 4 traces back to traceability — the ability to reconstruct, months or years later, exactly what was done, by whom, under what specification, for a specific device.
Practical implications for a first-time implementation
For a manufacturer building a QMS from scratch, or migrating from ISO 9001 to ISO 13485, clause 4 sets the scaffolding that every later clause depends on. A few practical consequences worth planning for early:
- Write the quality manual as a genuine map, not a copy-paste exercise. It should reference where each procedure lives and show how processes interact — design controls into production, complaints into CAPA, CAPA into management review.
- Set up the medical device file structure before design work accelerates. Retrofitting a device file after multiple design changes have already happened is far more time-consuming than building the referencing structure from day one.
- Define retention periods per product family, with a documented rationale. Because the appropriate period depends on device lifetime, risk classification and the regulatory regime in force, this decision should be made deliberately and recorded — not left as an unstated assumption.
- Build document control into your existing tools rather than bolting it on later. Version control, approval workflows and obsolete-document archiving are far easier to enforce from the start than to retrofit once dozens of procedures are already in circulation.
- Treat outsourced processes as part of your QMS, not outside it. Quality agreements with contract manufacturers, sterilizers or calibration labs need to specify exactly what control you retain and how conformity is verified.
// Demo IgeraIndustria — QMS documentation query
QA Manager: Which procedure defines our obsolete-document retention rule, and does it apply to the Class IIb catheter line?
IgeraIndustria: Retention rule defined in QP-04 Control of Documents, section 5.3: at least one obsolete controlled copy retained for the product's defined retention period. For the Class IIb catheter line, retention period is set at device lifetime (8 years per Device File DF-021) plus 2 years, per DF-021 section 3, last reviewed 2026-03-10. Source: QP-04, section 5.3; DF-021, section 3.
Auditor: Show me the current quality manual reference for how complaints feed into CAPA.
IgeraIndustria: Quality Manual QM-01, section 6.2, Process Interaction Diagram: complaint handling (QP-11) feeds CAPA (QP-12) via nonconformity trigger NC-T3; CAPA outputs feed design change evaluation (QP-07) when device-related. Source: QM-01, section 6.2.
Common audit findings and mistakes on clause 4
- Quality manual copied from a template with generic process descriptions that don't reflect the organization's actual process interactions or exclusions.
- Undefined or unjustified retention periods — a blanket "we keep everything for X years" statement with no link to device lifetime, risk class or applicable regulatory minimum.
- Missing or incomplete medical device files — files that don't reference all required elements (labeling, manufacturing specifications, servicing procedures where applicable) for every device type or family.
- No evidence of obsolete-document control — outdated procedures still circulating on shop floors or in shared drives without a clear superseded marker or controlled archive.
- Outsourced processes without a documented control mechanism — a contract manufacturer or sterilization supplier is used, but there is no quality agreement or defined verification method showing how conformity is assured.
- Records that are difficult to retrieve — legible and complete records exist, but the indexing or storage system means staff cannot produce them promptly when an auditor requests a sample.
- Regulatory requirements not identified per market — the QMS documentation doesn't show which regulatory requirements apply in each jurisdiction where the device is placed, leaving a gap between clause 4.1's requirement and the actual documentation trail.
Frequently asked questions about ISO 13485 clause 4
Is a quality manual mandatory under ISO 13485 even for a small manufacturer?
Yes. Unlike ISO 9001:2015, which no longer names the quality manual as a mandatory document, ISO 13485:2016 clause 4.2.2 explicitly requires one, regardless of organization size. The manual's depth can scale to the size and complexity of the business, but its core content — scope with justified exclusions, reference to documented procedures, and description of process interaction — is required either way.
How long do we need to keep quality records under ISO 13485?
The standard sets a floor — at least the lifetime of the device as defined by the organization, and not less than a minimum period from release, or as required by applicable regulation, whichever is longer — but the exact number of years depends on your product's defined lifetime, its risk classification, and the specific regulatory regime it falls under. Because this varies by product and jurisdiction, treat the exact retention period as something to determine and document per device family with your regulatory affairs function, rather than a single fixed rule you can apply everywhere.
What is the difference between the quality manual and the medical device file?
The quality manual (clause 4.2.2) describes the QMS as a whole — its scope, structure and process interactions. The medical device file (clause 4.2.3) is product-specific: a reference structure per device type or family containing or pointing to the specification, manufacturing, packaging, labeling and servicing documentation for that particular product. One describes the system; the other documents the product within that system.
Do we need to keep obsolete versions of our procedures?
Yes. Clause 4.2.4 requires retaining at least one copy of obsolete controlled documents for a defined period, precisely because a manufacturer may later need to show exactly what procedure or specification governed production of a specific batch or device at a given point in time. This is a more explicit requirement than what ISO 9001 asks for.
Does clause 4 require us to document every regulatory requirement in every country we sell to?
Clause 4.1 requires the organization to identify applicable regulatory requirements relevant to the QMS and to the markets in which the device is intended to be supplied, and to build the QMS to address them. The exact scope and format of that documentation depends on how many markets you operate in and how those regulatory regimes differ — this is an area where working with a regulatory affairs specialist or your notified body/regulatory consultant is strongly advisable rather than assuming a generic approach will suffice.
Can we outsource part of our QMS processes and still be compliant with clause 4?
Yes, ISO 13485 explicitly allows outsourcing of processes, but the organization remains fully responsible for conformity of the outsourced work to the standard and to applicable regulatory requirements. Clause 4.1 requires you to define the type and extent of control applied to the outsourced process, typically documented through a quality agreement, supplier qualification records, and ongoing monitoring evidence.
How is clause 4 different if we are transitioning from ISO 9001 rather than starting fresh?
The main gaps to close are usually the mandatory quality manual (if it was dropped under a 2015-style ISO 9001 implementation), the medical device file structure (which has no ISO 9001 equivalent), explicit retention of obsolete documents, and device-lifetime-linked record retention. Existing ISO 9001 document control and record control processes are a reasonable starting point, but each typically needs to be tightened to meet ISO 13485's more prescriptive requirements.
Disclaimer: This article is for general informational purposes and does not constitute certification, regulatory or legal advice. ISO 13485 requirements, retention periods and regulatory obligations vary by product risk classification, intended market and applicable law. Before implementing or updating your QMS documentation, consult a qualified quality/regulatory affairs consultant or your notified body.
Struggling to keep your quality manual, device files and records aligned across audits?
IgeraIndustria answers directly from your own QMS documents — quality manual, device files, procedures and records — citing the exact source, so your team can find the right clause reference in seconds instead of searching shared drives.
View ISO 13485 solution
Expert ISO 13485 · Updated 2026-09-25