FDA Quality Management System Regulation (QMSR)
QMSR: Quality Management System Requirements (§820.10 incorporating ISO 13485:2016 Sec. 4-8)

FDA Quality Management System Regulation (QMSR) QMSR-820.10: Requirements for a Quality Management System - ISO 13485:2016 Sections 4-8 incorporation (§820.10)

Section 820.10 establishes the substantive QMS requirements by requiring compliance with clauses 4 to 8 of ISO 13485:2016, which §820.7 incorporates by reference. Manufacturers must implement: ISO 13485:2016 SECTION 4 General QMS requirements + documentation (Quality Manual + Medical Device File + control of documents + records); SECTION 5 Management responsibility + customer focus + quality policy + planning + responsibility / authority / communication + management review; SECTION 6 Resource management (provision of resources + human resources + infrastructure + work environment + contamination control); SECTION 7 Product realization (planning + customer-related + design and development - the medical-device 'design controls' parallel + purchasing + production and service provision + control of monitoring + measuring equipment); SECTION 8 Measurement + analysis + improvement (monitoring + measurement + control of nonconforming product + analysis of data + improvement - including CAPA Sections 8.5.2 + 8.5.3). The QMSR does not reproduce the standard: it incorporates ISO 13485:2016 by reference and adds FDA-specific provisions, among them the clarification of concepts in §820.15, control of records in §820.35 and device labelling and packaging controls in §820.45. NB: §820.10 also clarifies that ISO 13485:2016 internal-audit + management-review requirements (Sections 8.2.4 + 5.6) apply to the QMSR.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 60 controls across 33 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ACQS-3-1 Safe and Effective Care
  • ACQS-8-2 Clinical Governance
  • ACQS-8-3 Continuous Improvement
  • ACQS-8-4 Risk Management

HITECH Act · 3 controls

  • HITECH-Coord-HIPAA-Privacy-Security-Cures-ONC HITECH Coordination with HIPAA Privacy Rule + HIPAA Security Rule (Verified Separately) + 21st Century Cures Act + ONC
  • HITECH-Enforcement-CMP-Tiers-StateAGs-OCR HITECH 4-Tier Civil Monetary Penalty Structure, State AGs Enforcement and HHS OCR Settlements
  • HITECH-SubtitleD-Breach-Notification-BA-Direct-Liability HITECH Subtitle D - Breach Notification Rule (45 CFR Part 164 Subpart D), Business Associate Direct Liability, Subcontractors
  • ISO-15189-5.6 Risk management
  • ISO-15189-7.4 Post-examination processes
  • ISO-15189-8.4 Control of records

MDS2 (Medical Device) · 3 controls

  • MDS2-Audit-Logging-AUDT-Integrity-IGAU-Cybersecurity-Risk-CYBR-Monitoring MDS2 Audit Controls + AUDT + Integrity + IGAU + Cybersecurity Risk + CYBR + Continuous Monitoring
  • MDS2-PHI-Data-Handling-DATA-Storage-STCF-Transmission-TXCF-TXIG-Encryption-FIPS MDS2 PHI Handling + DATA + STCF Storage + TXCF Transmission + TXIG Integrity + Encryption + FIPS
  • MDS2-Person-Node-Authentication-Authorization-Auto-Logoff-AUTH-PAUT-NAUT MDS2 Authentication + Authorization + Auto Logoff + PAUT + NAUT + AUTH + Identity Management
  • EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29)
  • EHDSREG-3 Secondary Use - Health Data for Research and Innovation
  • EHDSREG-5 Cross-Border Health Data Flows
  • CA-10 Selects and Develops Control Activities
  • CA-12 Deploys Through Policies and Procedures
  • FDBR-704 Exemptions (§501.704)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • IATF16949-Clause10-Improvement-Nonconformity-CorrectiveAction-Problem-ErrorProof IATF 16949 Clause 10 - Improvement + Nonconformity + Corrective Action + Problem Solving + Error Proofing + Continual Improvement
  • IATF16949-Clause4-Context-Scope-CustomerSpecific-ProductSafety IATF 16949 Clause 4 - Context of Organization + QMS Scope + Customer Specific Requirements + Product Safety
  • IEC62304-4.1 Quality Management System
  • IEC62304-9.6 Analyze Problems for Trends
  • AQAP2110-7 Production, Special Processes, Inspection, Testing, and Records
  • AQAP2110-8 Internal Audit, Management Review, Corrective Action, CofC, and Continual Improvement

SWIFT CSCF · 2 controls

  • SWIFTCSCF-1 Restrict Internet Access and Protect Critical Systems (Objective 1)
  • SWIFTCSCF-3 Physically Secure the Environment (Objective 3)
  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • TEFCAREC-2 Privacy, Security, Minimum Necessary
  • AS9100D-10.2 Nonconformity and Corrective Action
  • DIQ-2 Data Quality Management
  • IS.AR.210 Findings and Corrective Actions
  • GAMP5-Risk-CriticalThinking Risk-Based Approach, Critical Thinking and 5 Key Concepts
  • GGAP-IFA-AllFarmBase-Mgmt-Workers-Env-Trace GLOBALG.A.P. IFA v6 All Farm Base (AF): Management, Workers, Environment, Traceability and Food Safety
  • ICAO-ANX17-Chap3-QualityControl-Audits-Inspections-Tests-Certification-Training ICAO Annex 17 Chapter 3 - National Quality Control Programme + Audits + Inspections + Tests + Surveys + Certification + Aviation Security Training Programme (ASTP)
  • 60601-1.12 Accuracy of controls and instruments
  • IMO-MSC-FAL-Recover-BackupRestore-ContinuityOfNavigation-LessonsLearned-Drills IMO MSC-FAL Recover Function - Backup and Restore + Continuity of Navigation + Continuity of Cargo Operations + Continuity of Propulsion + Lessons Learned + Drills + Resilience

ISO/IEC 27014:2020 · 1 control

  • 27014-5.6 Continuous improvement
  • NAIC-1 NAIC Model Law Adoption, Scope, and Licensee Definitions
  • PICSGMP-1 Chapter 1: Pharmaceutical Quality System (PQS) and Quality Risk Management
  • 2.5.2 Verification Activities
  • SOCI-SECTOR-HEALTH Healthcare and medical sector

South Korea ISMS-P · 1 control

  • ISMSP-MS-04 Management Review and Improvement
  • UNESCO-AI-PA11 Health and Social Well-Being
  • VPSHR-3 Implementation Guidance and Reporting
  • SO2.5 Health information systems strengthening

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in QMSR: Quality Management System Requirements (§820.10 incorporating ISO 13485:2016 Sec. 4-8)

Query this from an agent

The graph holds this control, the 60 it maps to, and the evidence behind each claim, over MCP and REST.