Industry

ISO 13485 Clause 4: QMS and Documentation Requirements

Equip IgeraSolutions
September 25, 2026
9 min read
ISO 13485 Clause 4: QMS and Documentation Requirements
🎧 Listen with AI Voice

2-minute executive summary

⚡ Quick Answer in 30s

ISO 13485 clause 4 demands a documented QMS, quality manual and tightly controlled records — stricter than ISO 9001. Here's what auditors check.

✓ Citing current regulationsSee detailed guide below ↓

ISO 13485 · Medical devices QMS series

ISO 13485 Clause 4: QMS and Documentation Requirements

Clause 4 of ISO 13485:2016 requires a medical device manufacturer to establish, document, implement and maintain a quality management system, and to keep it effective throughout the product lifecycle. Compared with ISO 9001, clause 4 demands a more prescriptive documentation structure — a mandatory quality manual, tighter control of documents and records, and retention rules tied to the lifetime of the device — because the standard exists to protect patient safety, not just customer satisfaction. This guide walks through what clause 4 actually requires, why its documentation bar sits higher than ISO 9001's, and where manufacturers most often lose points in an audit.

ISO 13485 treats documented information as objective evidence of safety, not administrative overhead

Where ISO 9001 allows a lean, risk-based approach to documentation, ISO 13485 clause 4 expects a defined quality manual, a documented QMS structure, and records that can be traced back to a specific device, batch or design decision — because a gap in documentation can translate directly into a gap in traceability if something goes wrong in the field.

Structure of clause 4: general requirements and documentation

Clause 4 is split into two main subclauses:

  • 4.1 General requirements: the obligation to establish, document, implement and maintain a QMS, and to keep it effective, including outsourced processes and application of a risk-based approach to QMS processes.
  • 4.2 Documentation requirements: what documented information the QMS must contain, starting with the quality manual, and how documents and records are controlled — subclauses 4.2.1 (general), 4.2.2 (quality manual), 4.2.3 (medical device file) and 4.2.4/4.2.5 (control of documents and records).

4.1 General requirements: the QMS as a controlled, risk-based system

Clause 4.1 requires the organization to document the QMS processes and their sequence and interaction, determine appropriate methods for controlling those processes, and ensure the availability of resources and information necessary to support their operation. Two elements set the medical device context apart from a generic quality standard:

  • A risk-based approach to the QMS itself: the organization must apply a risk-based approach to the control of processes needed for the QMS, appropriate to the medical device(s) concerned — risk thinking is not confined to the product design, it runs through how the quality system is governed.
  • Control of outsourced processes: where a process is outsourced (contract manufacturing, sterilization, calibration, distribution), the organization remains responsible for conformity, and must define the type and extent of control applied, documented in a quality agreement or equivalent.
  • Regulatory awareness: the organization must identify applicable regulatory requirements for each market where the device will be placed, and reflect those requirements in the QMS — a dimension ISO 9001 does not carry in the same explicit way.

Practical tip

Map your QMS process interactions early — a simple process map showing design controls, purchasing, production, CAPA and post-market surveillance, and how they feed each other, is one of the first documents an auditor will ask for. If a manufacturer cannot show how a customer complaint flows into CAPA and, where relevant, into design change, that gap is treated as a system failure, not a paperwork oversight.

4.2.1 and 4.2.2: the documented QMS and the mandatory quality manual

Clause 4.2.1 requires QMS documentation to include the quality policy and quality objectives, a quality manual, documented procedures and records required by the standard, documents the organization determines are needed to ensure effective planning, operation and control of its processes, and any other documentation specified by applicable regulatory requirements.

Clause 4.2.2 then makes something explicit that ISO 9001:2015 no longer requires by name: a documented quality manual. The manual must include, or reference, the scope of the QMS (with justification for any exclusion or non-application of requirements, which under ISO 13485:2016 may apply to aspects of Clauses 6, 7 and 8 — Clauses 4 and 5 themselves cannot be excluded), the documented procedures or reference to them, and a description of the interaction between QMS processes. In practice, the quality manual is the map an auditor uses to navigate the rest of the system — it is the document that ties policy, procedures and process interaction together into one coherent reference.

4.2.3: the medical device file

This is one of ISO 13485's clearest departures from ISO 9001. Clause 4.2.3 requires the organization to establish and maintain a file for each medical device type or family, containing or referencing documents generated to demonstrate conformity to the standard and compliance with applicable regulatory requirements. In practice this file typically references or contains:

  • General description of the device, intended use/purpose, and labeling, including instructions for use.
  • Specifications for the product.
  • Specifications or procedures for manufacturing, packaging, storage, handling and distribution.
  • Procedures for measuring and monitoring.
  • Requirements for installation, where applicable.
  • Procedures for servicing, where applicable.

ISO 9001 has no equivalent concept — it has no notion of a per-product regulatory file, because it is not designed around a specific regulated product category. The medical device file is effectively the technical backbone that regulatory submissions and design history files build on.

4.2.4 and 4.2.5: control of documents and control of records

Both ISO 9001 and ISO 13485 require document and record control, but ISO 13485 is markedly more prescriptive on the mechanics:

  • Review and approval before issue, with a defined approval authority for each document.
  • Identification of changes and the current revision status of documents, so that superseded content cannot be mistaken for current.
  • Retention of at least one obsolete controlled copy for a defined period — the standard explicitly calls out retaining obsolete documents, which ISO 9001 does not require in the same way, because a manufacturer may need to reconstruct exactly what specification or procedure was in force when a specific device or batch was produced.
  • Records must remain legible, readily identifiable and retrievable, with controls for identification, storage, protection, retrieval, retention and disposition defined in a documented procedure.

On retention periods specifically: ISO 13485 requires records to be retained for at least the lifetime of the medical device as defined by the organization, but not less than two years from the date of release of the product by the organization, or as specified by applicable regulatory requirements — whichever is longer. What "lifetime of the device" means in practice varies significantly by product risk classification, expected clinical use and the specific regulatory regime the device is placed under, so a manufacturer needs to determine and justify the applicable retention period for each product family rather than assume a single fixed number of years applies across the board.

Why ISO 13485's documentation bar sits above ISO 9001's

Documentation element ISO 9001:2015 ISO 13485:2016
Quality manual Not explicitly required by name Explicitly mandatory, with defined minimum content
Per-product file No equivalent requirement Medical device file mandatory per device type/family
Obsolete document retention Left to the organization's discretion Explicitly required to retain at least one obsolete copy
Record retention period Not specified by the standard itself Tied to device lifetime and a defined regulatory minimum
Regulatory documentation Not addressed Explicit requirement to identify and document applicable regulatory requirements

The reasoning behind the gap is straightforward: ISO 9001 is a generic customer-satisfaction and process-effectiveness standard applicable to any sector, whereas ISO 13485 exists specifically to support consistent design, production and post-market control of products that can affect patient health. Every extra documentation requirement in clause 4 traces back to traceability — the ability to reconstruct, months or years later, exactly what was done, by whom, under what specification, for a specific device.

Practical implications for a first-time implementation

For a manufacturer building a QMS from scratch, or migrating from ISO 9001 to ISO 13485, clause 4 sets the scaffolding that every later clause depends on. A few practical consequences worth planning for early:

  • Write the quality manual as a genuine map, not a copy-paste exercise. It should reference where each procedure lives and show how processes interact — design controls into production, complaints into CAPA, CAPA into management review.
  • Set up the medical device file structure before design work accelerates. Retrofitting a device file after multiple design changes have already happened is far more time-consuming than building the referencing structure from day one.
  • Define retention periods per product family, with a documented rationale. Because the appropriate period depends on device lifetime, risk classification and the regulatory regime in force, this decision should be made deliberately and recorded — not left as an unstated assumption.
  • Build document control into your existing tools rather than bolting it on later. Version control, approval workflows and obsolete-document archiving are far easier to enforce from the start than to retrofit once dozens of procedures are already in circulation.
  • Treat outsourced processes as part of your QMS, not outside it. Quality agreements with contract manufacturers, sterilizers or calibration labs need to specify exactly what control you retain and how conformity is verified.

// Demo IgeraIndustria — QMS documentation query

QA Manager: Which procedure defines our obsolete-document retention rule, and does it apply to the Class IIb catheter line?

IgeraIndustria: Retention rule defined in QP-04 Control of Documents, section 5.3: at least one obsolete controlled copy retained for the product's defined retention period. For the Class IIb catheter line, retention period is set at device lifetime (8 years per Device File DF-021) plus 2 years, per DF-021 section 3, last reviewed 2026-03-10. Source: QP-04, section 5.3; DF-021, section 3.

Auditor: Show me the current quality manual reference for how complaints feed into CAPA.

IgeraIndustria: Quality Manual QM-01, section 6.2, Process Interaction Diagram: complaint handling (QP-11) feeds CAPA (QP-12) via nonconformity trigger NC-T3; CAPA outputs feed design change evaluation (QP-07) when device-related. Source: QM-01, section 6.2.

Common audit findings and mistakes on clause 4

  • Quality manual copied from a template with generic process descriptions that don't reflect the organization's actual process interactions or exclusions.
  • Undefined or unjustified retention periods — a blanket "we keep everything for X years" statement with no link to device lifetime, risk class or applicable regulatory minimum.
  • Missing or incomplete medical device files — files that don't reference all required elements (labeling, manufacturing specifications, servicing procedures where applicable) for every device type or family.
  • No evidence of obsolete-document control — outdated procedures still circulating on shop floors or in shared drives without a clear superseded marker or controlled archive.
  • Outsourced processes without a documented control mechanism — a contract manufacturer or sterilization supplier is used, but there is no quality agreement or defined verification method showing how conformity is assured.
  • Records that are difficult to retrieve — legible and complete records exist, but the indexing or storage system means staff cannot produce them promptly when an auditor requests a sample.
  • Regulatory requirements not identified per market — the QMS documentation doesn't show which regulatory requirements apply in each jurisdiction where the device is placed, leaving a gap between clause 4.1's requirement and the actual documentation trail.

Frequently asked questions about ISO 13485 clause 4

Is a quality manual mandatory under ISO 13485 even for a small manufacturer?

Yes. Unlike ISO 9001:2015, which no longer names the quality manual as a mandatory document, ISO 13485:2016 clause 4.2.2 explicitly requires one, regardless of organization size. The manual's depth can scale to the size and complexity of the business, but its core content — scope with justified exclusions, reference to documented procedures, and description of process interaction — is required either way.

How long do we need to keep quality records under ISO 13485?

The standard sets a floor — at least the lifetime of the device as defined by the organization, and not less than a minimum period from release, or as required by applicable regulation, whichever is longer — but the exact number of years depends on your product's defined lifetime, its risk classification, and the specific regulatory regime it falls under. Because this varies by product and jurisdiction, treat the exact retention period as something to determine and document per device family with your regulatory affairs function, rather than a single fixed rule you can apply everywhere.

What is the difference between the quality manual and the medical device file?

The quality manual (clause 4.2.2) describes the QMS as a whole — its scope, structure and process interactions. The medical device file (clause 4.2.3) is product-specific: a reference structure per device type or family containing or pointing to the specification, manufacturing, packaging, labeling and servicing documentation for that particular product. One describes the system; the other documents the product within that system.

Do we need to keep obsolete versions of our procedures?

Yes. Clause 4.2.4 requires retaining at least one copy of obsolete controlled documents for a defined period, precisely because a manufacturer may later need to show exactly what procedure or specification governed production of a specific batch or device at a given point in time. This is a more explicit requirement than what ISO 9001 asks for.

Does clause 4 require us to document every regulatory requirement in every country we sell to?

Clause 4.1 requires the organization to identify applicable regulatory requirements relevant to the QMS and to the markets in which the device is intended to be supplied, and to build the QMS to address them. The exact scope and format of that documentation depends on how many markets you operate in and how those regulatory regimes differ — this is an area where working with a regulatory affairs specialist or your notified body/regulatory consultant is strongly advisable rather than assuming a generic approach will suffice.

Can we outsource part of our QMS processes and still be compliant with clause 4?

Yes, ISO 13485 explicitly allows outsourcing of processes, but the organization remains fully responsible for conformity of the outsourced work to the standard and to applicable regulatory requirements. Clause 4.1 requires you to define the type and extent of control applied to the outsourced process, typically documented through a quality agreement, supplier qualification records, and ongoing monitoring evidence.

How is clause 4 different if we are transitioning from ISO 9001 rather than starting fresh?

The main gaps to close are usually the mandatory quality manual (if it was dropped under a 2015-style ISO 9001 implementation), the medical device file structure (which has no ISO 9001 equivalent), explicit retention of obsolete documents, and device-lifetime-linked record retention. Existing ISO 9001 document control and record control processes are a reasonable starting point, but each typically needs to be tightened to meet ISO 13485's more prescriptive requirements.

Disclaimer: This article is for general informational purposes and does not constitute certification, regulatory or legal advice. ISO 13485 requirements, retention periods and regulatory obligations vary by product risk classification, intended market and applicable law. Before implementing or updating your QMS documentation, consult a qualified quality/regulatory affairs consultant or your notified body.

Struggling to keep your quality manual, device files and records aligned across audits?

IgeraIndustria answers directly from your own QMS documents — quality manual, device files, procedures and records — citing the exact source, so your team can find the right clause reference in seconds instead of searching shared drives.

View ISO 13485 solution

Expert ISO 13485 · Updated 2026-09-25

#iso 13485 clause 4#iso 13485 documentation requirements#quality management system medical devices#iso 13485 quality manual#iso 13485 vs iso 9001 documentation#iso 13485 record retention#medical device QMS documented information#iso 13485 general requirements

Ask this article

IA 2026

Igera's AI answers questions citing the facts and regulations in this article

2 of 2 free queries

Suggested questions (click to test):

Diagnóstico Interactivo 60s

Technical Compliance & Industrial Operations Diagnostic

Analyze speed of access to regulations (CTE, OSH, CE) in your plant or jobsite

Pregunta 1 de 3

How do technicians and operators access safety protocols and manuals?

Was this article helpful?

⚙️IgeraIndustriaOperations Template
GUÍA DESCARGABLE (TXT)

Preventive Maintenance & ISO 9001/45001 Industrial Checklist

Floor inspection template for machine operations, failure tracking and unplanned downtime reduction.

  • Shift inspection standardization for plant operators
  • Up to 40% faster anomaly response times
  • Full traceability for ISO audits and HSE compliance

Instant download · No card · 100% spam-free

Share this article

Help spread knowledge by sharing this content with your network