Skip to main content
Services
Audit & Certification
ISO Gap AnalysisInternal AuditAudit PreparationAfter the AuditClose Nonconformities
Standards
ISO 9001 Quality ManagementISO 9001:2026 TransitionISO 14001 Environmental ManagementISO 45001 Occupational Health & SafetyISO 27001 Information SecurityISO 42001 AI ManagementISO 13485 Medical Devices
Industries & Support
Industry SolutionsMedical DevicesMechanical Engineering & ProductionIT, SaaS & AIManagement System MaintenanceExternal QMRQM Training
Industries
All IndustriesMechanical Engineering & ProductionAutomotive SuppliersLaser Optics, Photonics & SemiconductorsIndustrial Service ProvidersMedical DevicesIT, SaaS & AI
FundingFAQKnowledgeAboutContactSend emailCall now
DE/EN
Free Consultation
Medical Devices

ISO Consulting for Medical Devices

In medical devices, quality management must be regulatorily robust and practical. I support ISO 13485, audit preparation and systematic evidence management.

  • ISO 13485
  • MDR context
  • CAPA
  • Suppliers

Documentation that stands up in audits and helps daily work.

Medical device companies need clear processes for development, changes, suppliers, complaints, CAPA and traceability. At the same time, the system must not become so heavy that teams bypass it.

I help translate requirements into lean, verifiable workflows and build critical records early.

The connection between technical documentation, risk management, post-market information, supplier control and QMS is especially important. If these elements are maintained separately, audit gaps appear quickly.

Quality management documents for medical devices and ISO 13485

The compliance landscape in medical devices.

Medical device companies do not work with ISO 13485 alone. Depending on market role, EU MDR interfaces, ISO 14971 risk management, software lifecycle processes, validations, clinical or technical evidence, supplier approvals and CAPA processes need to fit together.

The challenge is rarely the existence of single documents. What matters is whether changes, complaints, incidents, supplier information and risk assessments are linked in a traceable way. Notified bodies, customers and internal auditors look closely at this connection.

Growing companies also face different documentation logics across development, regulatory affairs, quality, purchasing and production. A resilient QMS brings these perspectives into one audit-ready workflow.

What Sternberg Consulting provides for medical devices.

I translate ISO 13485 requirements into concrete procedures, roles and evidence that fit your product, company size and maturity. This includes document control, change control, CAPA, supplier evaluation, training records, internal audits and management review.

Existing ISO 9001 structures can be used where they are robust. Where ISO 13485 requires more depth, gaps are closed deliberately with clear evidence logic instead of oversized manuals.

Before certification, surveillance or customer audits, I check whether critical records are available, consistent and explainable. Teams are prepared not only in documentation, but also in typical audit questions.

What auditors check in medical devices.

Medical device audits rarely check isolated procedures only. What matters is whether technical documentation, risk assessment, QMS processes and operational records fit across the lifecycle.

01

Risk management link

Are product and process risks assessed traceably, and are changes, complaints, supplier events and CAPA connected to this risk logic?

02

CAPA effectiveness

Are root cause analysis, immediate corrections, corrective actions and effectiveness checks clearly separated and closed with reliable evidence?

03

Change control

Is it clear which technical, regulatory and process impacts a change has and who must approve it before implementation?

04

Supplier status

Are critical suppliers approved, evaluated and monitored, including outsourced processes, technical specifications and relevant certificates?

05

Traceability

Can batches, components, inspections, releases and complaint information be linked so later decisions remain understandable?

06

Audit interviews

Can development, quality, purchasing, production and management explain how requirements are implemented and improved in daily work?

Approach in medical devices

Implementation follows product, supply chain role and regulatory pressure.

  1. Clarify regulatory context

    Product class, role, customer requirements and existing processes are assessed.

  2. Close QMS gaps

    Critical procedures, responsibilities and records are prioritized.

  3. Increase audit readiness

    Internal audits, management review and CAPA evidence are prepared.

After the audit: secure CAPA, evidence and system maintenance.

Findings from medical device audits must not be closed in isolation. Each nonconformity should be checked for cause, risk link, affected processes, possible product or supplier impact and effectiveness verification.

I help translate audit findings into CAPA, change needs, training, supplier actions or management decisions. The audit then becomes not only a closed report, but a verifiably improved QMS.

Get a quick view of what fits your situation.

Briefly describe your situation, the relevant standard and your timeline. You will receive a personal assessment and a concrete suggestion for the next step.

Frequently asked questions

Does ISO 13485 consulting replace regulatory legal advice?

No. Consulting supports quality management and audit readiness. Regulatory or legal detail questions should be checked separately where needed.

Can existing ISO 9001 processes be used?

Often yes, but ISO 13485 adds requirements for documentation, risk links, validation, suppliers and evidence.

Which records are especially critical?

Risk management files, change records, CAPA effectiveness, supplier evaluations, validations, training records and the link between complaints, post-market information and improvement actions are often critical.

How does ISO 13485 fit software medical devices?

For software medical devices, QMS, risk management, development process, change control, verification, validation and operational interfaces need to be considered together.

When should ISO 13485 be checked before a customer audit?

Several weeks before the audit is useful so CAPA, supplier records, trainings, changes and management review can be prepared effectively.

How does an ISO 13485 system stay current after certification?

Through regular internal audits, maintained CAPA lists, supplier monitoring, change assessment, training planning and a management review that derives real decisions from data and findings.