ISO 13485:2016
Quality management system – ISO 13485:2016

ISO 13485:2016 4.1: General requirements

The organization documents a quality management system and keeps it effective as the standard and the applicable regulatory requirements demand, recording the regulatory role or roles it holds (for example manufacturer, authorized representative, importer or distributor). It determines which processes the system needs and how they apply across the organization, taking those roles into account; controls those processes using an approach based on risk; and determines the order in which they run and how they interact. For every process it: determines the criteria and methods needed to run and control it effectively; makes sure the resources and information needed are available; carries out the actions required to reach the planned results; monitors, measures as appropriate and analyses the process; and keeps the records needed to show conformity to the standard and compliance with regulatory requirements. Any change to these processes is assessed for its effect on the quality management system and on the medical devices produced under it, and is controlled. Where the organization outsources a process that affects product conformity, it monitors and controls that process and remains responsible for conformity; the controls are proportionate to the risk and to the outside party's ability to meet requirements, and include written quality agreements. The organization documents procedures for validating software used within the quality management system, applied before first use and after changes, with an approach proportionate to the risk of using the software, and keeps records of the validation.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 112 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 22000:2018 · 10 controls

ISO 9001:2015 · 10 controls

ISO 14004:2016 · 8 controls

ISO 19011:2018 · 7 controls

ISO 14001:2015 · 6 controls

ISO 27005:2022 · 6 controls

ISO/IEC TR 24028:2020 · 6 controls

  • 8.1 General: vulnerabilities, threats and challenges
  • 8.3.1 AI specific privacy threats: general
  • 9.1 General: mitigation measures
  • 9.10.1 Testing and evaluation: general
  • 9.3.1 Explainability: general
  • 9.4.1 Controllability: general

ISO 22301:2019 · 5 controls

ISO 27701:2019 · 5 controls

  • 0.1 General
  • 5.1 General
  • 6.1 General
  • 7.1 General
  • 8.1 General

ISO 31000:2018 · 5 controls

ISO 37301:2021 · 5 controls

  • 7.2.1 Competence: general
  • 7.5.1 Documented information: general
  • 9.1.1 Monitoring, measurement, analysis and evaluation: general
  • 9.2.1 Internal audit: general
  • 9.3.1 Management review: general

ISO/IEC 23894:2023 · 5 controls

ISO 10007:2017 · 3 controls

ISO 26000:2010 · 3 controls

  • ISO-26000-4.1 General
  • ISO-26000-5.1 General
  • ISO-26000-7.1 General

ISO 27001:2022 · 3 controls

  • 0.1 General
  • 9.2.1 Internal audit: general
  • 9.3.1 Management review: general
  • ISO-15189-6.1 General
  • ISO-15189-7.1 General

ISO 37001:2016 · 2 controls

ISO/IEC 38500:2024 · 2 controls

  • 7.1 Framework: general
  • 7.2.1 General: the elements

ISO/IEC 42001:2023 · 2 controls

COPPA · 1 control

  • COPPA-312.3 General Requirements: Five Core Obligations
  • 60601-1.5.1 General requirements for testing

ISO 10005:2005 · 1 control

  • 5.1 General: what the quality plan should contain

ISO 10006:2003 · 1 control

  • 7.1 Product realization: General

ISO 22320:2018 · 1 control

  • ISO-22320-4.1 General

ISO 56002 · 1 control

  • ISO-56002-10.1 General
  • 27006-5.1 General Requirements for Certification Bodies

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Quality management system – ISO 13485:2016

Query this from an agent

The graph holds this control, the 112 it maps to, and the evidence behind each claim, over MCP and REST.