Risk management link
Are product and process risks assessed traceably, and are changes, complaints, supplier events and CAPA connected to this risk logic?
In medical devices, quality management must be regulatorily robust and practical. I support ISO 13485, audit preparation and systematic evidence management.
Medical device companies need clear processes for development, changes, suppliers, complaints, CAPA and traceability. At the same time, the system must not become so heavy that teams bypass it.
I help translate requirements into lean, verifiable workflows and build critical records early.
The connection between technical documentation, risk management, post-market information, supplier control and QMS is especially important. If these elements are maintained separately, audit gaps appear quickly.
Medical device companies do not work with ISO 13485 alone. Depending on market role, EU MDR interfaces, ISO 14971 risk management, software lifecycle processes, validations, clinical or technical evidence, supplier approvals and CAPA processes need to fit together.
The challenge is rarely the existence of single documents. What matters is whether changes, complaints, incidents, supplier information and risk assessments are linked in a traceable way. Notified bodies, customers and internal auditors look closely at this connection.
Growing companies also face different documentation logics across development, regulatory affairs, quality, purchasing and production. A resilient QMS brings these perspectives into one audit-ready workflow.
I translate ISO 13485 requirements into concrete procedures, roles and evidence that fit your product, company size and maturity. This includes document control, change control, CAPA, supplier evaluation, training records, internal audits and management review.
Existing ISO 9001 structures can be used where they are robust. Where ISO 13485 requires more depth, gaps are closed deliberately with clear evidence logic instead of oversized manuals.
Before certification, surveillance or customer audits, I check whether critical records are available, consistent and explainable. Teams are prepared not only in documentation, but also in typical audit questions.
Medical device audits rarely check isolated procedures only. What matters is whether technical documentation, risk assessment, QMS processes and operational records fit across the lifecycle.
Are product and process risks assessed traceably, and are changes, complaints, supplier events and CAPA connected to this risk logic?
Are root cause analysis, immediate corrections, corrective actions and effectiveness checks clearly separated and closed with reliable evidence?
Is it clear which technical, regulatory and process impacts a change has and who must approve it before implementation?
Are critical suppliers approved, evaluated and monitored, including outsourced processes, technical specifications and relevant certificates?
Can batches, components, inspections, releases and complaint information be linked so later decisions remain understandable?
Can development, quality, purchasing, production and management explain how requirements are implemented and improved in daily work?
Processes, roles, document control and records are structured to fit product and company risk.
More on ISO 13485 system setupNonconformities, corrective actions and effectiveness checks are documented traceably.
More on CAPA and nonconformitiesApprovals, evaluations, technical evidence and traceability are connected so critical supplier risks remain visible.
More on Suppliers and traceabilityBefore certification, surveillance or customer audits, critical evidence and interviews are prepared.
More on Audit preparationImplementation follows product, supply chain role and regulatory pressure.
Product class, role, customer requirements and existing processes are assessed.
Critical procedures, responsibilities and records are prioritized.
Internal audits, management review and CAPA evidence are prepared.
Findings from medical device audits must not be closed in isolation. Each nonconformity should be checked for cause, risk link, affected processes, possible product or supplier impact and effectiveness verification.
I help translate audit findings into CAPA, change needs, training, supplier actions or management decisions. The audit then becomes not only a closed report, but a verifiably improved QMS.
Briefly describe your situation, the relevant standard and your timeline. You will receive a personal assessment and a concrete suggestion for the next step.
No. Consulting supports quality management and audit readiness. Regulatory or legal detail questions should be checked separately where needed.
Often yes, but ISO 13485 adds requirements for documentation, risk links, validation, suppliers and evidence.
Risk management files, change records, CAPA effectiveness, supplier evaluations, validations, training records and the link between complaints, post-market information and improvement actions are often critical.
For software medical devices, QMS, risk management, development process, change control, verification, validation and operational interfaces need to be considered together.
Several weeks before the audit is useful so CAPA, supplier records, trainings, changes and management review can be prepared effectively.
Through regular internal audits, maintained CAPA lists, supplier monitoring, change assessment, training planning and a management review that derives real decisions from data and findings.