When and how to build your medical device Quality Management System (QMS)
Many of the most significant challenges in Medical Device Development come down to how we best manage uncertainty. We have a clear picture of what we’re aiming for, namely an approved and adopted device that is demonstrably safe and effective and is used and reimbursed within our target healthcare markets. How to get there however is harder to define but left up to us as developers to determine for ourselves, a difficult task particularly if we’re new to medical device development.
When, how, and how extensively to implement our Quality Management System is a key example here. With the introduction in February 2026 of the FDA’s Quality Management System Regulation, ISO-13485 becomes the reference point for a suitable medical device quality management system in both the EU and US.
While ISO-13485 discusses what is expected of a Quality Management System – i.e. the requirements in terms of the content of the QMS and document controls, responsibilities of management, resource management, product realisation process, and on-going measurement, analysis and improvement of the system itself. What isn’t covered is when or how to implement the requirements, or how to adapt them to our individual product and business.
This leaves us determining this for ourselves – managing a large element of uncertainty – but what approach should we take in the absence of clear guidance? How do we know we’re implementing the right thing, in the right way, at the right time?
When - A risk-based approach
As with so much in the world of medical devices and combination products, the most straightforward answer is to take a risk-based approach. What we’re really asking ourselves is where we want to fall within an undefined grey area (Figure 1). At either end of the continuum we have two extreme cases, namely:
Implement a full QMS from the first idea. Theoretically possible, and even optimal, to demonstrate full design justification and compliance across the development journey. The challenge here is that QMS implementation requires time and money (typically 9-12 months of work) that is often unavailable in our early medical device journey. Moreover, key elements are yet to be developed, e.g. an organisation and management structure, and we may ultimately build a sophisticated QMS for a product which isn’t viable
Implement a QMS at regulatory approval submission. Also possible, but risky and likely to have negative consequences. What notified bodies and health authorities requires is a QMS that is appropriate, effective, and implemented, alongside a design history file that tracks design decisions from beginning to end. Implementing a QMS this late in the process means we are unable to demonstrate effectiveness or implementation, and are absent a comprehensive design justification – all of which means extra costs, in the form of remediation, repeat work, or in extreme cases fines and product recalls
Mapping this onto our overall product development journey, we have a situation like that in Figure 2 – both an earliest and latest implementation point and increasing levels of risk the more we delay.
In every case, the earliest point at which a QMS can be implemented will always be the lowest risk and most cost effective, presuming the idea is one that successfully becomes an approved and adopted product. It ensures that the risk of failure in either our ISO-13485 certification or medical devices approval is lowest and minimises the need for any repeat or additional work demonstrating design justification and full development under a sufficient QMS.
In the messy reality of medical device development though, this approach is not always possible, and it’s reasonable to balance the risks and costs against other business drivers. In addition, the depth of record keeping needed for a robust QMS can get in the way of rapid exploration, testing, and design iterations that characterise the earliest stages of healthcare innovation.
So where does that leave us? Implementing your QMS as early as you can is always the best idea – while it may feel costly and time consuming at the time, it will likely save you multiples of that cost and time down the line. As a minimum, implementing the elements of ISO-13485 related to product design and development (Sections 7.1 to 7.4) will give you a greatly increased chance of demonstrating your design history and design justification effectively during regulatory approval, and minimise the risk of the need for repeat work, or major non-conformities in your submission.
It’s also reasonable to build your QMS over time, stating with the most important and relevant parts. Whilst the requirements around product design and development are relevant from the very start of the development process, Section 7.5 focused on Production is likely only to become relevant later in your development lifecycle. In practice, you will always have a gap between the build of your QMS and any certification, as you need to demonstrate operation of the QMS over several months. This leaves space for you to evolve your QMS alongside your development, as long as you also observe the relevant Section 8 requirements around Measurement, Analysis and Improvement.
What becomes difficult to justify is delaying your build out beyond the point at which you have locked down on a single implementation of your product, moving from exploration to exploitation, and into your near commercial prototype. From this point on it is essential to have tight design control in place, and so a full QMS, to avoid later stage remediation or repeat work.
Be also mindful here that not all elements on ISO-13485 are relevant to all projects – the key example here being Section 7.5.5 requirements around records for sterilised products, which are only relevant for products that require sterilisation.
This reaches into another key point to understand about QMS implementation. Part of the “how” question that ISO-13485 leaves open if the format within which a QMS must be documented. All options are possible, from a completely paper-based system, through controlled electronic records, to specific electronic QMS systems. What should be remembered here though is that the design and implementation of a QMS is always specific to the needs of an individual organisation, as described in the ISO-13485 handbook, and driven by factor such as the organisation’s environment, needs, goals, product, processes, size, structure, and appliable regulatory requirements.
So whilst the QMS can be implemented in any format, “off-the-shelf” QMS implementations need to be treated with the upmost care, and even if configurable, need to be carefully reviewed, alongside a justification, to ensure that they meet the needs of your specific organisation and product.
To be clear, a “clean” bespoke build of a QMS in one go, from the very start, will always be the most effective option, but if that is not possible, then taking a risk-based approach to building out a system over time is also a viable option. Key is that at the time of certification and or device approval, you have a system that is appropriate, effective, and implemented, demonstrably has been throughout the design and development of your product, and has resulted in a complete design history and justification. This leaves us with the optional implementation points outlined in Figure 2 between idea and near commercial prototype - within which lies the best overall, risk-based approach for your own business, product, and circumstances.
How – An Approach to Developing your QMS
When building out and running your QMS, there are several levels of documentation that need to be developed, as outlined in Figure 3:
Quality Manual – this is the overarching document that describes and documents your Quality Management System. It includes key elements like the scope and goals of your QMS, any exclusions as well as the justifications behind them, and a description of the processes within the QMS, and how they interact, as well as the structure of your QMS as a whole
Quality Procedures – These include the detailed descriptions of the key procedures within your QMS that added together drive its day-today operation. Key examples here include your design and development process, your supplier audit procedures, management review procedures, etc.
Standard Operating Procedures (SoPs) – The next level down are your Standard Operating Procedures, step-by-step instructions for key tasks within the QMS that ensure accurate and repeatable operation of activities like manufacturing, testing, and inspection
Forms and Templates – Pre-structured documents design to capture and record key data during the design, development, and manufacture of your medical device. This may include forms or templates for design reviews, audits, inspection, training records, etc.
Records – These are the output documents generated by applying your QMS to the design, development and manufacture of your medical device. This includes, in particular, your Design History File, Design Transfer File, Risk Management File, etc
Taken altogether the documents outline both the Quality system and how it operates, as well as the output of that system in terms of design and development documentation.
When implementing a Quality Management System, few organisations start completely from scratch, there are likely already in place formal, or informal processes and procedures that meet the requirements of aspects of e.g. ISO-13485. Crucial however is that effective implementation of the QMS requires support and buy-in across the organisation, from the CEO downwards. Whilst this may be straightforward in a small organisation, in a larger one this may in and of itself be a complex process.
Overall, implementation requires a staged process that builds the required organisational buy in, defines what is needed, implements it, and continually. Therefore, the key stages and activities include:
1. Building the Foundation – implementing the activities that ensure an effective QMS is built, including:
Buy-in: Communicating throughout the organisation the need, value, and goals, and getting top to bottom management and organisational buy-in
Requirements: Determining the requirements of the QMS for your organisation – identifying, justifying, and documenting which elements of ISO-13485 are essential, optional, or redundant
Review: An internal review to determine what processes already exist, formally or informally, and the extent to which they meet or fall short of the requirements of ISO-13485
Gaps: Identifying the gaps that exist against ISO-13485 and determining what processes and documentation need to be developed to fill them
Priorities: Identify what elements of ISO-13485 are the priority to implement given your organisational reality, goals, and stage of development
Plan: Develop the implementation plan that takes you from where you are to an appropriate, effective, and demonstrably implemented QMS
2. QMS Development – Implement the plan, build the documents
Build: Write, define, and document the processes and procedures that will make up your appropriate, effective, and implemented QMS.
3. Implementation – Make the system real and working
Implement: Establish the complete processes, procedures, SOPs, forms, and templates that make up your QMS
Train: Implement training to ensure that the key members of your organisation know how to implement and comply with the QMS as designed
Operate: Run the QMS on your medical device(s) to demonstrate the system as it operates in reality
4. Review and Optimise – Implementing the system alone is not enough, you also need to demonstrate that it achieves what is needed as implemented in the real day-to-day of your business
Internal audit: Perform an internal audit to assess the performance of the QMS against its intentions. Assess all the outcomes, processes, and procedures against the needs of ISO-13485
Management Review: Management have ultimate responsibility for the adequacy, effectiveness and implementation of the QMS, and so must perform their own review into how the system operates
Corrective Action: Where any gaps occur between the QMS as intended and how it operates in reality
5. Certification audit – Prepare for certification
Ensure appropriate, effective, and implemented: Perform a final review to ensure your system is appropriate, effective and implemented against the needs of ISO-13485
Get certified: Fine your certified body, submit your system for review, audit and certification, and take it through the certification process
6. Continual use, review, and improvement
Your QMS should be regularly reviewed and updated both to repair any performance drift over time, or to adapt and adjust to any changes on regulation
Summary
As with so many things in Medical Device or Combination Product development, navigating the Quality Management space requires us to take a lot of the responsibility of determining and implementing what we need to do. While standards such as ISO-13485 outline what a QMS needs to achieve, determine how and when to implement our QMS is left up to us.
It’s important then to be able to understand the requirements in our own context – organisational, people, and product – and use a risk-based approach that balances that context against our own goals and the requirements of regulation.
And this is not an easy task! The responsibility is ours, but now always the knowledge. That’s why if you’re in doubt, it also pays to get help from the experts - such as an ISO-13485 consultant, or QMS consultant. In a situation where an early and complete QMS will likely save you multiples of the expended time and cost downstream, and open the route for your product to be approved for market, then help is always time and money well spent.
Are you trying to implement your own QMS and seeking help on the journey? Feel free to message us here for a 1:1 no-obligation chat to see how we can help you