Internal audit
Clause 8.2.4 (in most editions' numbering) requires periodic internal audits to verify that the QMS conforms to the planned arrangements, to the requirements of ISO 13485 itself, and to the QMS requirements the organisation has set for itself — and that the system is effectively implemented and maintained. Audits are planned with a programme that takes into account the status and importance of the processes and areas audited, and the results of previous audits. Findings must lead to timely correction and, where warranted, corrective action, and follow-up verification should confirm that the action taken was effective.
Monitoring and measurement of processes and product
Two related but distinct activities sit here. Process monitoring checks that the processes of the QMS achieve their planned results — using suitable methods that reflect the ability and criticality of each process. Product monitoring checks that product characteristics have been met at appropriate stages, with records that identify the person authorising release of product for the next stage or for delivery, and keeps that identification traceable. For product that requires implantation or that carries elevated risk, records of monitoring and measurement typically need to be more detailed and more clearly traceable to enable investigation if something goes wrong downstream.
Nonconforming product must be identified and controlled to prevent unintended use or delivery. The organisation documents a procedure that defines the controls, responsibilities and authorities for identification, documentation, segregation, evaluation and disposition of nonconforming product, including — where applicable — product discovered after delivery. Rework is permitted but must itself be controlled, documented and, where it could affect conformity, re-verified. Where nonconforming product is detected after delivery or use has started, the organisation must document the actions taken in response, including any advisory notice or field action, in a manner consistent with its post-market surveillance obligations.
Analysis of data
Clause 8.4 requires the organisation to determine, collect and analyse appropriate data to demonstrate the suitability, adequacy and effectiveness of the QMS, and to identify opportunities for improvement. The standard specifies sources this analysis must draw on, including feedback, conformity to product requirements, characteristics and trends of processes and product (including opportunities for preventive action), suppliers, audits, and service reports where servicing is a specified requirement. This is where trend analysis lives: a single complaint may not warrant CAPA, but a pattern across a product family, a supplier or a process step usually does.
CAPA: corrective and preventive action
The CAPA system is the mechanism through which Clause 8's other activities produce change. It has two distinct halves, and mixing them up is one of the most common sources of confusion:
- Corrective action eliminates the cause of a nonconformity that has already occurred, to prevent recurrence. It requires reviewing the nonconformity, determining its causes, evaluating the need for action to ensure it does not recur, determining and implementing the needed action, documenting the results, and reviewing the effectiveness of the corrective action taken.
- Preventive action eliminates the cause of a potential nonconformity — one that has not yet occurred — to prevent its occurrence. It follows a parallel logic: identify potential nonconformities and their causes, evaluate the need for action, implement it, document it, and review its effectiveness.
ISO 13485 explicitly requires that corrective and preventive action be evaluated for any effect on the ability to meet regulatory requirements and on product safety and performance, and that changes resulting from CAPA be reviewed and, where required, validated or verified before implementation. This regulatory link is one of the clearest differences from a generic quality system: a CAPA in a medical device company is not just a quality record, it is potentially a regulatory event.
2
Separate, distinct disciplines within one CAPA system: corrective action (react to a nonconformity that already happened) and preventive action (act on a potential nonconformity before it happens). Auditors routinely find these conflated into a single generic "action" record, which weakens traceability for both.
The key point most teams get wrong: "improvement" in ISO 13485 vs ISO 9001
This is one of the most frequently misunderstood aspects of ISO 13485, and it is worth stating precisely. ISO 9001 treats continual improvement of the QMS as an explicit, standing requirement — organisations are expected to actively and continuously enhance the suitability, adequacy and effectiveness of their management system over time. ISO 13485 does not carry that same explicit continual-improvement mandate. Instead, ISO 13485 requires the organisation to demonstrate that the QMS is effectively implemented and maintained, and that its processes achieve their planned results consistently, in a regulated environment where uncontrolled or unplanned change to a validated process or product can itself introduce risk.
This is not a licence to be static. Clause 8 still requires the organisation to identify and implement necessary changes through CAPA, to analyse data for opportunities to improve, and to act on nonconformities and audit findings. What is different is the framing and the constraint: in ISO 13485, any change — including one aimed at "improving" something — has to be evaluated for its effect on product safety, performance and regulatory conformity, and controlled accordingly, rather than pursued as an open-ended, continuous optimisation of the system for its own sake. In practice, this means changes to a validated process typically require a documented change control and, where appropriate, re-validation, rather than being rolled out simply because a trend analysis suggested an efficiency gain.
Practical impact: what this changes in how the system runs day to day
For a quality team, the ISO 9001 vs ISO 13485 distinction on improvement translates into concrete operational habits:
- CAPA effectiveness reviews are not optional paperwork — auditors expect to see that the organisation went back and checked whether the corrective action actually worked, with objective evidence, not just a closed record.
- Trend data (complaints, nonconformities, audit findings, process monitoring results) needs a defined review cadence and a documented threshold for when a trend triggers CAPA, rather than being reviewed only when something goes visibly wrong.
- Changes proposed through CAPA or data analysis go through change control before implementation, with an assessment of impact on regulatory status and on validated processes — "we improved it" is not, on its own, sufficient justification in an audit.
- Complaint handling and CAPA cannot be siloed from each other or from risk management — an auditor will trace a single complaint through investigation, disposition of any nonconforming product, CAPA (if triggered), and back into risk documentation, and expects that trail to be coherent.
// Demo IgeraIndustria — Clause 8 query
Quality Manager: Do we have an open CAPA linked to the Class IIb device complaint trend from last quarter, and what was the documented root cause?
IgeraIndustria: CAPA-2025-0041, opened from Complaint Trend Report CTR-Q3, references three complaints tied to the same lot family. Root cause per the investigation record: a seal specification tolerance drift identified during process monitoring. Corrective action and effectiveness review status, plus the linked risk file update, are documented in the same record — cited with the exact section reference.
Common audit findings on Clause 8
Auditors and notified body assessors repeatedly flag a recognisable set of issues in this area:
- CAPA records closed without an effectiveness review, or with an effectiveness review that is not based on objective evidence.
- Corrective and preventive action conflated into one generic process, making it unclear whether the organisation is reacting to an existing problem or preventing a potential one — and whether the required steps for each were actually followed.
- Complaint investigations that don't clearly link to the reportability determination — no documented rationale for why an event was, or was not, escalated under post-market surveillance or vigilance requirements.
- Internal audit programmes that don't reflect risk — the same shallow checklist applied to every area regardless of criticality or history of findings.
- Data analysis that is descriptive but not actionable — trends are charted and reported but never clearly tied to a decision about whether CAPA is warranted.
- Nonconforming product records with gaps in the disposition chain — segregation, evaluation and authorisation for release not clearly traceable to a named, authorised individual.
- Changes implemented following a CAPA without documented change control or re-validation of the affected process.
Most of these findings share a common thread: the individual activities (complaints, audits, monitoring, CAPA) exist and are documented, but the links between them — the traceability that shows one feeds into the next — are weak or missing. That traceability is exactly what an auditor is trained to pull on.
Where IgeraIndustria fits
Clause 8 generates a lot of interlinked documentation: complaint logs, audit reports, monitoring records, nonconformity dispositions, CAPA files, data analysis reports. Finding the exact record that answers an auditor's question — or confirming, before the audit, that the trail from a complaint to its CAPA to its effectiveness review is complete — is largely a retrieval problem. IgeraIndustria indexes a company's own QMS documents and answers questions in seconds, citing the exact source document and section, rather than requiring a manual search across procedures, complaint logs and CAPA records.
Spending hours tracing a complaint through to its CAPA and effectiveness review before an audit? IgeraIndustria answers directly from your own QMS documents, with the exact source cited.
Try it free for 14 days
Summary
- Clause 8 covers feedback/complaints, internal audit, process and product monitoring, control of nonconforming product, data analysis and CAPA.
- Complaint handling connects to post-market surveillance and vigilance obligations, but exact reporting timelines and triggers depend on the applicable regulation and device classification — always verify against the current regulatory text for the relevant market.
- The key ISO 9001 difference: ISO 13485 requires the QMS to be demonstrably effective and maintained, not continually improved as an explicit, standalone objective — changes must be controlled and evaluated for regulatory and safety impact, not pursued as open-ended optimisation.
- The most common audit findings involve broken traceability between activities (complaint → CAPA → effectiveness review) rather than any single missing activity.
- IgeraIndustria indexes CAPA files, complaint logs, audit reports and procedures, answering with the exact document and section cited.
Disclaimer
This article is for informational purposes only and does not constitute certification, legal or regulatory advice. ISO 13485 certification, interpretation of specific clauses, and post-market surveillance/vigilance reporting obligations depend on your product classification, target markets and current regulatory text. Consult a qualified quality/regulatory consultant or your notified body before making compliance decisions.
FAQ
What is the main purpose of Clause 8 in ISO 13485?
Clause 8 sets out how an organisation monitors, measures and analyses its QMS and its products, and how it acts on the results — through feedback, internal audit, nonconforming product control, data analysis and CAPA — to demonstrate that the system is effective and stays that way.
Does ISO 13485 require continual improvement like ISO 9001?
No, not in the same explicit sense. ISO 13485 requires the organisation to demonstrate that the QMS is effectively implemented and maintained. It still requires acting on nonconformities, complaints and data through CAPA, but any resulting change must be controlled and assessed for its effect on regulatory conformity and product safety, rather than pursued as an open-ended continual-improvement objective.
What is the difference between corrective and preventive action?
Corrective action addresses a nonconformity that has already occurred, to stop it recurring. Preventive action addresses a potential nonconformity that has not yet occurred, to stop it from happening in the first place. Both require identifying the cause, evaluating and implementing action, and reviewing effectiveness.
Do all complaints have to be reported to a regulator?
Not automatically. The organisation must evaluate each complaint against the post-market surveillance and vigilance reporting criteria that apply to its device and market, and document that determination. Exact criteria and timelines vary by jurisdiction and device classification, so this should be checked against the current applicable regulation.
Can a CAPA be closed as soon as the corrective action is implemented?
No. ISO 13485 requires a review of the effectiveness of the corrective (or preventive) action taken, meaning objective evidence that the action actually addressed the cause, before the CAPA can reasonably be considered closed.
The organisation's own documented procedure defines the responsibilities and authorities for this decision. What Clause 8 requires is that the authorisation is by a defined, competent role, that it is recorded, and that any product requiring re-verification after rework is actually re-verified before release.
How does IgeraIndustria help with Clause 8 documentation?
IgeraIndustria is an AI assistant that answers directly from a company's own QMS documents — complaint logs, audit reports, CAPA files, monitoring records — citing the exact source, so quality teams can trace a record such as a complaint through to its CAPA and effectiveness review in seconds instead of searching manually across systems.