🏆 ISO 13485 & QMS

ISO 13485:2016 vs the 2003 version: the 7 structural changes to remember

The migration from the 2003 version of ISO 13485 to the 2016 version has often been reduced to a documentary reformatting. This is a mistake that auditors spot without difficulty. Seven structural changes distinguish the two texts: risk-based approach extended to the QMS, software validation, strengthened supplier control, explicit integration of regulatory requirements. A QMS genuinely compliant with the 2016 version does not look like a pre-March 2019 one.

12 min read

The 2016 version of ISO 13485 is the version that has applied since the end of the transition period in March 2019. More than seven years. Yet, one observation comes up regularly during certification or surveillance audits: in many SME medical device manufacturers, the migration from the 2003 version was superficial. A reformatting of procedures, a few added paragraphs, a new table of contents aligned with the 2016 structure. The underlying logic, however, has not changed.

This is precisely what experienced auditors detect within a few hours. Seven points of structural divergence between the two versions generate recurring findings. Here they are, in the order in which they most often weaken a QMS in practice.

1. The risk-based approach extended to the entire QMS

This is the most important conceptual break between the two versions. The 2003 version confined the risk-based approach to product risk management, as structured by ISO 14971. The risk management file was a technical deliverable, distinct from the quality management system.

The 2016 version changes the paradigm. Section 4.1 explicitly requires “a risk based approach to the control of the appropriate processes needed for the quality management system”. Concretely: process planning, the frequency of internal audits, the level of control over a supplier, the depth of a validation, the extent of receiving inspections. Each of these decisions must be able to rely on a documented risk analysis, however simple.

A QMS compliant with the 2016 version does not set the frequency of its internal audits out of habit or convenience. It justifies it by the level of risk associated with the audited process. A sterilization process will be audited more frequently than a human resources management process, and this difference will be traced, justified, defensible in an audit.

This is a difference in managerial posture, not merely documentary. In an audit, the finding often materializes through a simple question: “How did you determine this frequency?” If the answer is “We have always done it this way” or “It is annual for everyone”, the problem is laid bare.

2. Regulatory requirements explicitly integrated into the QMS

The 2003 version implicitly included regulatory compliance within its scope. The 2016 version makes it an explicit and documented obligation: the organization must identify the regulatory requirements applicable to its activities and products, and demonstrate how its QMS addresses them.

Annex A of the standard confirms this: section 4.1 adds the need to “meet customer and applicable regulatory requirements for safety and performance”. The scope (section 1) specifies that the term “regulatory requirements” includes “laws, regulations, ordinances or directives”.

Concretely, a QMS that makes no reference to Regulation (EU) 2017/745 (MDR), or to the national texts applicable to its devices, is non-compliant with the 2016 version, even if its processes are otherwise well described and applied. Mapping regulatory requirements is no longer an optional good practice: it is a requirement of the standard.

This change has a direct implication for documentation: the quality policy, the quality manual or its equivalent, and the key procedures must explicitly anchor the QMS in the applicable regulatory framework. In practice, this also assumes a monitoring mechanism: section 5.6.2, item l), makes “new or revised applicable regulatory requirements” a mandatory input to management review. A QMS that does not track the evolution of the regulatory framework is structurally non-compliant.

For medical device manufacturers operating under the MDR, this convergence between standard and regulation is a powerful lever: a QMS well aligned with the 2016 version already meets a significant share of the requirements of Article 10(9) of the MDR.

3. Validation of software used in the QMS

Section 4.1.6 is one of the most frequently overlooked provisions during migrations. It requires that software used within the QMS be validated before use, and after any significant change.

The scope is broad and often poorly understood. It concerns not only software embedded in medical devices (which falls under design in §7.3 and under IEC 62304), nor production software (covered by §7.5.6). Section 4.1.6 targets any software whose failure could affect product conformity within the QMS itself: an ERP, a document management system, an audit planning tool, a spreadsheet used to calculate cleaning limits or to track non-conformities.

The standard specifies that “the specific approach and activities associated with software validation and revalidation shall be proportionate to the risk associated with the use of the software”. This principle of proportionality is essential. Validating a complaint-tracking spreadsheet does not require the same level of formalism as validating an ERP integrated into batch release. But in both cases, a documented procedure, acceptance criteria, tests, recorded results and a release approval are required.

In organizations that have shifted to digital tools (cloud document management, SaaS ERP, collaborative tools) without formalizing this approach, this finding is systematic. It becomes critical when the software is automatically updated by the vendor: without a defined revalidation process, each update represents an uncontrolled risk.

4. Strengthened, risk-proportionate supplier control

Section 7.4.1 of the 2016 version introduces a proportionality requirement absent from the 2003 version. It is no longer merely a matter of having a list of approved suppliers and carrying out periodic evaluations: the level of control exercised over each supplier must be justified by the risk that its failure represents for the quality and conformity of the final device.

Annex A of the standard summarizes the change: §7.4.1 “focuses the criteria for the selection of the supplier on the effect of the performance of the supplier on the quality of the medical device, the risks associated with the medical device and the conformity of the product to applicable regulatory requirements”. The version adds requirements for monitoring, re-evaluation, and actions to take when purchasing requirements are not met.

Concretely, this implies several obligations. Initial selection criteria must be documented and applied in a traceable manner. Initial evaluations must be recorded, not merely planned. Periodic re-evaluations must take place, be traced, and their conclusions must feed into decisions to maintain or withdraw qualification. A supplier of critical raw materials or sterilized components cannot be treated with the same level of control as a supplier of office supplies. The 2016 version requires this differentiation to be explicit and documented.

In an audit, the typical finding is a supplier file where all providers are evaluated with the same generic grid, without any modulation by risk. This uniform formalism may look rigorous; it is in fact non-compliant.

5. Feedback integrated into post-production activities

Section 8.2.1 of the 2016 version restructures the feedback process. This is an important change of logic, which Annex A summarizes in two points: feedback must now come “from production as well as post-production activities”, and the information gathered must “serve as an input into risk management for monitoring and maintaining the product requirements”.

Under the 2003 version, customer complaints could be handled as isolated events: receipt, analysis, response, closure. The 2016 version requires them to be embedded in a structured loop. Data from complaints, reports, field returns and satisfaction surveys must feed a process enabling the detection of trends, the identification of weak signals, and the triggering of corrective or preventive actions.

The standard adds a specific requirement for manufacturers subject to regulatory post-production monitoring obligations: “If applicable regulatory requirements require the organization to gain specific experience from post-production activities, the review of this experience shall form part of the feedback process” (§8.2.1).

For manufacturers under the MDR, this clause creates a direct bridge with post-market surveillance obligations (Articles 83 to 86) and vigilance (Articles 87 to 92). A feedback process compliant with §8.2.1 of the 2016 version constitutes the operational basis for the post-market surveillance plan required by the MDR. The two systems are not synonymous, but the first structurally feeds the second.

In practice, the most frequent finding is a complaints process and a post-production monitoring process compartmentalized into two documentary silos without formalized interaction. The 2016 version requires these processes to be interfaced.

6. Formalized control of outsourced processes

Section 4.1.5 requires the organization to monitor and control outsourced processes whenever they affect product conformity. The 2003 version was less prescriptive on this point.

The wording of the standard is precise: “Controls shall be proportionate to the risk involved and the ability of the external party to meet the requirements in accordance with 7.4. The controls shall include written quality agreements.”

The common mistake is to consider that a subcontracting contract is enough to demonstrate control. This is not necessarily the case. The “written quality agreements” must specify the arrangements for verifying that the provider meets the organization’s requirements: audits, performance reviews, receiving inspections, quality data transmission. They must also specify how the results of this monitoring are recorded and taken into account in requalification decisions.

A structured quality agreement can meet this requirement. So can an internal procedure for managing outsourced processes. What matters is not the form of the document, but the reality of the control exercised and its traceability.

This change resonates directly with the MDR, which explicitly holds the manufacturer accountable for controlling its supply chain, including for activities entrusted to third parties. Article 10(9) of the MDR requires the manufacturer to establish, document, implement and maintain a QMS covering in particular “resource management, including selection and control of suppliers and sub-contractors”.

7. Enriched mandatory inputs to management review

Section 5.6.2 of the 2016 version moves to 12 mandatory inputs, compared to 7 in the 2003 version. This extension is not cosmetic. Three additions reflect the evolution of the standard’s philosophy.

The handling of complaints (item b) becomes a distinct input, separated from general feedback (item a). Under the 2003 version, complaints were buried in “customer feedback”. The 2016 version requires them to be presented at management review as a category in their own right, with their own trends and conclusions.

Reporting to regulatory authorities (item c) is an entirely new input. Management must be informed, at management review, of the reports made to the competent authorities. This is a logical consequence of integrating regulatory requirements into the scope of the QMS: if regulatory compliance is an objective of the system, regulatory reports are a performance indicator of it.

New or revised regulatory requirements (item l) are the last input added. Management review must incorporate an analysis of developments in the applicable regulatory framework. Without this input, management steers the QMS without visibility over the changes to come or under way.

The outputs have also been enriched. Section 5.6.3 comprises 4 mandatory outputs, including a new one: “changes needed to respond to new or revised applicable regulatory requirements” (item c). Management review no longer merely acknowledges regulatory developments; it must decide on the actions to be taken in response.

In an audit, a management review that does not cover these 12 inputs and 4 outputs generates a finding. More fundamentally, a review that does not rely on this data deprives top management of information essential to steering the QMS effectively.

In summary

These seven developments are not editorial adjustments. They reflect a more mature quality management philosophy, oriented toward the proactive control of risks, the traceability of decisions and the integration of the regulatory framework at the heart of the QMS.

A QMS genuinely aligned with the 2016 version does not resemble, in its operating logic, one built on the 2003 version. The documentary structure may be similar. The processes may bear the same names. But the way decisions are made, justified and traced is fundamentally different.

It is often during a certification renewal audit, or a first audit by a new notified body, that the gaps of a superficial migration become visible. It is better to identify them yourself beforehand. A pre-audit focused on these seven points makes it possible to measure the real gap between the QMS as documented and the requirements as they are actually formulated in the standard.

Topics covered:

ISO 13485:2016 ISO 13485 version 2003 ISO 13485 changes medical device QMS ISO 13485 certification ISO 13485 audit ISO 13485 migration QMS software validation ISO 13485 supplier control ISO 13485 management review MDR 2017/745 outsourced processes