Start with the product’s quality system
ISO 13485 addresses quality management systems for organizations involved in medical devices. The applicable procedures and responsibilities need to be established within the manufacturer’s quality system. ISO’s description of ISO 13485:2016
For a software delivery team, the practical question is how everyday engineering produces the records that system needs. Agree with the quality owner how requirements, design reviews, verification and release decisions will be recorded. Do this before the release is waiting for approval.
Our team has participated in ISO 13485 audits for companies developing Class II and Class III software medical devices. We answered auditors’ questions and substantiated our contribution with evidence. That experience informs how we support delivery; it is not a claim that ViewCo holds organizational ISO certification or leads regulatory submissions.
Follow one change all the way through
Consider a change that adds confirmation after a report is submitted to an integration platform. A reviewer should be able to understand why the change was needed, what the team designed and what was tested.
A useful record trail connects:
- The requirement and relevant risk considerations.
- The design decision and reviewed implementation.
- The verification method, environment and recorded result.
- Any unresolved issues and the decision about them.
- The software version and release approval record.
This is a practical example of an evidence trail, not an exhaustive ISO checklist. Your quality team determines the records and approvals required for your product.
Distinguish a test reference from a test result
A link to a test procedure shows where the method is documented. It does not establish that the test ran against the release under review.
Record which version was exercised, the relevant environment and the outcome. If a check used a simulator, say so. If a test is planned for staging, do not describe it as completed verification. This distinction helps reviewers assess what is known and what still needs work.
The same principle applies to automated tooling. A script that creates records can reduce repetitive work, but someone still needs to check that the records accurately reflect the change.
Keep the release story consistent
Release notes, change records and verification references should describe the same scope. When reviewer feedback changes that scope, update the affected records together.
In our report delivery engagement, engineering work included preparing eQMS release records and connecting design reviews with verification evidence. That put the technical result and its supporting records in front of reviewers together.
Bring delivery and quality into the same conversation
Our hands-on eQMS experience includes Greenlight Guru and ins2outs. Our team has also completed basic awareness training in ISO 13485:2016 and ISO 14971:2019. Training completion, audit participation and an organization’s certification are different claims.
We can support the engineering and quality-system work alongside your team. Your qualified specialists or separately scoped partners lead regulatory strategy, clinical validation and submissions.