bg_image
Comments Off on Medical Device Document Control: Meeting ISO 13485, 21 CFR Part 11 & the QMSR
Posted By

ClaudeAI

TAGS:

Medical device document control under ISO 13485, 21 CFR Part 11, and the QMSR (TLM)

For a medical device company, medical device document control isn’t a filing preference — it’s the system an FDA investigator and your notified body use to decide whether you’re in control of your product. And as of February 2, 2026, the bar moved: the FDA’s new Quality Management System Regulation (QMSR) replaced the old Quality System Regulation, and 21 CFR Part 820 now incorporates ISO 13485:2016 by reference. If your document control was built around the old QSR language, this is the moment to make sure it actually meets the standard your auditors now hold you to.

This guide covers what medical device document control has to do under ISO 13485 and 21 CFR Part 11, what an investigator actually pulls during an inspection, and — the part the enterprise vendors skip — how a small or mid-sized device company meets all of it without a pharma-scale budget.

What changed with the QMSR (and what it means for document control)

The headline: instead of spelling out its own quality-system requirements, Part 820 now points to ISO 13485:2016. In practice, your document control is now judged against the ISO standard’s requirements directly — the same standard your notified body already audits for CE/MDR. For most well-run device firms this is more alignment than upheaval, but it removes any daylight between “FDA-compliant” and “ISO 13485-compliant” document control. They’re now the same target.

That target has two clauses at its core:

  • ISO 13485 Clause 4.2.4 — Control of documents: documents must be reviewed and approved before use, kept current and legible, changes reviewed and approved, and obsolete documents controlled to prevent unintended use.
  • ISO 13485 Clause 4.2.5 — Control of records: records must be created and kept to demonstrate conformity, and remain legible, identifiable, and retrievable — for defined retention periods tied to device lifetime.

Notice 13485 is stricter than ISO 9001 here: it explicitly requires documented procedures for document and record control, and it ties retention to the lifetime of the device. Vague “we control our documents” doesn’t survive contact with a 13485 audit.

What medical device document control actually has to do

Underneath the clauses, the job breaks into the same mechanics as any quality system — but with medical-device stakes attached:

  • One current, approved version, always. Every change creates a new controlled revision; the prior one is archived for traceability but never presented as current; obsolete revisions are pulled from use. For a device firm, “someone built to the wrong drawing revision” isn’t a finding — it’s a potential recall.
  • Controlled, approved change. Changes route through review and approval before release — not an in-place edit. Design and process changes especially must be traceable to who approved them and why.
  • Attributable electronic approvals. In an electronic system, approvals are captured as 21 CFR Part 11-compliant electronic signatures — attributable, permanently recorded, with the meaning of the signature captured.
  • A complete, exportable audit trail. Who created, reviewed, approved, released, and retired every document, time-stamped — the evidence an investigator asks for by name.
  • Records control with retention. Device history records, CAPA, complaints, and training records kept legible and retrievable for the device’s defined lifetime.

The documents and records an investigator will actually pull

When the FDA (or your notified body) is on-site, document control is where the inspection lives. Expect them to trace:

  • Your quality manual, procedures, and work instructions — current versions, properly approved.
  • The medical device file (ISO 13485’s controlled definition of the device and its production — the successor to the old Device Master Record concept).
  • Design controls and the design history file, and your risk management file (ISO 14971).
  • CAPA and complaint records, and the change history behind any of them.
  • Training records — proof that the people performing a controlled process are trained on the current revision of the procedure.

That last one is where a lot of small firms stumble. The investigator picks a released procedure and asks, “Show me who’s trained on this version.” If your training lives on a spreadsheet that’s out of sync with your document releases, you have a gap — no matter how good your documents are.

Facing an FDA inspection or notified-body audit and not sure your document control holds up? Book a 20-minute walkthrough →

21 CFR Part 11: what “electronic document control” has to prove

If you control documents electronically (and under the QMSR, essentially everyone does), Part 11 sets the rules for those electronic records and signatures to be trustworthy. In plain terms, your document control system needs to demonstrate:

  • Attributable, time-stamped audit trails that record actions without letting anyone quietly alter or delete the history.
  • Electronic signatures that are uniquely tied to one person, can’t be reused or transferred, and record the signer, the date/time, and the meaning of the signature (authored, reviewed, approved).
  • Access controls that limit who can create, change, and approve.

Part 11 isn’t a separate project bolted onto document control — it’s the property your document control has to have to count as evidence. A system built for medical devices bakes it in rather than leaving you to prove it.

Where small and mid-sized device companies actually get it right

Here’s the honest part the enterprise vendors won’t tell you: the requirements above are the same whether you’re a 30-person startup or a 3,000-person manufacturer. ISO 13485 and Part 11 don’t scale their expectations to your headcount. What does differ is what it takes to meet them — and this is where small medtech firms get sold the wrong thing. (If you’re comparing systems, our guide to the best document control software for ISO-certified firms covers how to choose.)

The market leaders in medical-device quality software are built (and priced) for large manufacturers. A small or early-commercial device company that licenses a pharma-scale eQMS often spends six figures and a year in configuration to use a fraction of it — and still struggles with the real failure point: adoption by a lean quality team.

What a small or mid-sized device company actually needs is document control that:

  • Meets 13485 and Part 11 out of the box — controlled review and release, Part 11 e-signatures, obsolete-document control, and a complete audit trail — without an enterprise deployment.
  • Ties training to each release automatically, so the investigator’s “prove they’re trained on the current version” is a one-click answer, not a spreadsheet reconciliation.
  • Flexes to how your team actually works rather than forcing a generic template — because the best system is the one your people will actually use.
  • Comes with real onboarding support, since adoption, not features, is what determines whether a small firm stays audit-ready between inspections.

That’s the profile TLM was built for: full ISO 13485 and 21 CFR Part 11-capable document control — versioning, controlled change, electronic signatures, obsolete-document handling, training tied to release, and an exportable audit trail — sized and priced for the small and mid-sized device company, with support that gets your team using it.

See medical-device document control on your own process →

Frequently asked questions

What is medical device document control?
Medical device document control is the system that governs the lifecycle of a device company’s controlled documents and records — creation, review, approval, release, revision, distribution, and retention — to meet ISO 13485 and, in the US, 21 CFR Part 820 (now the QMSR) and 21 CFR Part 11. It ensures only current, approved versions are in use and that every action is recorded as inspection-ready evidence.

Does ISO 13485 require a documented document-control procedure?
Yes. Unlike ISO 9001:2015, ISO 13485 explicitly requires documented procedures for control of documents (Clause 4.2.4) and control of records (Clause 4.2.5), including defined retention periods tied to the lifetime of the device.

How does the QMSR change document control for medical devices?
As of February 2, 2026, 21 CFR Part 820 incorporates ISO 13485:2016 by reference. In practice, your document control is now judged directly against ISO 13485’s requirements — the same standard your notified body uses — so US FDA and international expectations are aligned. Well-run 13485 document control already meets it.

What does 21 CFR Part 11 require for electronic document control?
Part 11 requires that electronic records and signatures be trustworthy: attributable, time-stamped audit trails that can’t be silently altered; electronic signatures uniquely tied to one person that capture the signer, date/time, and meaning; and access controls over who can create, change, and approve.

Do small medical device companies need a full eQMS for document control?
Not a pharma-scale one. The compliance requirements are the same at any size, but a small or mid-sized device firm is better served by a right-sized system that meets ISO 13485 and Part 11 out of the box, ties training to releases, flexes to its process, and comes with real onboarding support — since adoption, not feature count, is what keeps a lean team audit-ready.


Want to see ISO 13485 and Part 11-compliant document control working on one of your own procedures? Book a short walkthrough — bring a real document and we’ll run it through controlled change, electronic approval, and training assignment live to include the new AI review feature.  Watch Claude AI give it a compliance review, and edit the document with recommended tracked changes to support revision history and user training.  After your approval, Claude sends a copy to the DCO and cleans the draft for release.  Seeing is believing.

Simplify Compliance with Easy, Robust and AI-Powered QMS Software

Your business runs on a vast web of interrelated information, so your software systems should be able to do the same.